plsreadme

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it publishes markdown or text as public web links, which is useful but requires careful confirmation before use.

Install this only if you want your agent to create public, permanent links from markdown or text. Confirm before every upload, avoid secrets or private notes, and inspect or pin the npm MCP package if using the local `npx` setup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description includes broad trigger phrases such as "share this as a page" and "make this readable," which can match many ordinary user requests unrelated to intentional publication. In this skill's context, mistaken invocation is risky because the tool uploads content to a permanent, publicly accessible link, creating a real chance of accidental data exposure if the agent routes sensitive markdown or notes into this skill.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal