HTTP Retry - HTTP 重试机制

Security checks across malware telemetry and agentic risk

Overview

This is a small C HTTP retry sample with no hidden access, but it is incomplete and its retry guidance should be used carefully.

Reasonable to install as sample code or educational guidance. Do not use it unchanged for production HTTP, payments, transfers, account changes, or POST/PATCH retries; add idempotency keys, method-aware retry rules, real HTTP integration, tests, and clear failure handling first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation promotes automatic HTTP retries but does not warn that retrying non-idempotent operations such as POST, PATCH, or purchase/transfer actions can duplicate side effects. In a reusable skill, this omission can cause data corruption, duplicate transactions, or unintended repeated actions when users apply the mechanism broadly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal