Back to skill

Security audit

Media Bias News

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward news and media-bias lookup integration that uses a disclosed third-party API, with privacy caveats around sending queries or pasted URLs to MediaBias.news.

Install only if you are comfortable with your news searches, outlet names, domains, and article URLs being sent to MediaBias.news for lookup. Avoid pasting private, unpublished, or tracking-heavy URLs unless you intend that lookup to happen.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The README explicitly encourages plain HTTP requests to a third-party service and discusses querying publisher names, domains, and pasted article URLs, but it does not warn that those user-supplied identifiers will be transmitted off-platform to MediaBias.news. This is a real privacy/transparency issue because users may paste sensitive or private URLs into an agent, and the skill context increases risk slightly since news/article URLs can include private, unpublished, or tracking-laden links.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to overlap with routine requests like asking for the latest news, story summaries, or pasted URLs, which can cause the skill to auto-activate in many common conversations. That increases the chance of unintended outbound requests to a third-party service and can route user content or URLs to the external API when the user did not explicitly ask for this specific integration.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.