Summarize 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward summarize-CLI helper; the main risk is that files or URLs may be sent to configured AI or extraction providers.

Install only if you trust the Homebrew package source and the summarize CLI. Avoid using it on confidential, regulated, or secret-bearing files or internal URLs unless your chosen AI and extraction providers are approved for that data, and monitor API key usage and billing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly supports summarizing URLs, local files, and YouTube content via external model providers and optional fallback services, but it does not warn users that submitted content may be transmitted off-host. This creates a real privacy and data-handling risk because users may pass sensitive documents, internal URLs, or media under the assumption processing is local, when the tool is actually API-backed.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal