Back to skill

Security audit

Acedatacloud Api

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only API guide that asks users to use an AceDataCloud token, with no executable code or hidden behavior found.

Install if you want a guide for using AceDataCloud APIs. Treat any AceDataCloud token as a secret: store it in an environment variable or secret manager, avoid pasting real tokens into chats or source files, and redact tokens from logs and examples.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation repeatedly demonstrates direct token usage but provides no warning about secret handling, redaction, or avoiding hardcoding in source, prompts, and logs. In an agent setting, this can normalize unsafe credential practices and increase the chance that users expose live API tokens to third parties or commit them to code repositories.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.