Ai Chat

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for using AceDataCloud as an LLM API gateway; its main risk is that user prompts and API usage go to a third-party service.

Install only if you trust AceDataCloud and are comfortable sending prompts, images or image URLs, tool definitions, and related request metadata to that service and its downstream model providers. Use a dedicated revocable token, keep it out of code and logs, monitor billing, and avoid secrets or regulated data unless your organization has approved the provider's privacy and retention terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs users to send prompts, and later images, to a third-party API endpoint but provides no privacy or data-handling warning. This can lead users to unknowingly transmit sensitive data, proprietary content, or personal information outside their environment to an external service.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The authentication section tells users to export an API token but does not warn against hardcoding, logging, sharing, or committing credentials. This increases the chance of accidental token exposure through shell history, screenshots, source control, or copied examples.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal