Back to skill

Security audit

SnapPwd Secure Secret Sharing

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed secret-sharing helper, but users should be careful because it encourages sharing high-value credentials through a third-party service.

Install only if you trust SnapPwd and any optional CLI package. Use it for explicit, one-time sharing with verified recipients, avoid raw long-lived private keys when possible, prefer temporary or scoped credentials, and rotate or revoke sensitive credentials after sharing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is broad enough that the skill may activate whenever a user casually mentions sharing sensitive information, increasing the chance the agent steers users toward moving credentials, keys, or files through this workflow without sufficient confirmation or least-privilege checks. In a secret-sharing skill, overbroad activation is risky because it can normalize handling highly sensitive material and cause unintended collection or transfer of credentials.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The usage criteria include vague conditions like when a user 'needs to send sensitive data' or is 'troubleshooting,' which can cause the skill to activate in contexts where safer alternatives should be considered first. Because the skill is specifically about transmitting secrets, ambiguous boundaries materially increase the likelihood of unnecessary exposure of credentials or confidential files.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation explicitly encourages uploading highly sensitive material such as .env files, SSH private keys, and credential JSON files to a remote secret-sharing service without any warning, validation, or guidance on when this is unsafe. In the context of a skill designed to help agents share secrets, this normalizes risky handling of long-lived credentials and could lead users to exfiltrate crown-jewel secrets to third-party infrastructure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.