Back to skill

Security audit

Requesthunt

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed RequestHunt CLI workflow for collecting public user feedback and generating demand research reports, with normal external-service and API-key considerations.

Before installing, review the RequestHunt CLI installer/source if your environment requires strict supply-chain controls, use an environment variable or secured config for the API key, and remember that searches and scrape jobs use an external paid service and public user-generated content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Instruction Override

High
Category
Prompt Injection
Content
**Representative Quotes:**
> "Currently, when an Event Type is set to 'Requires Confirmation,' the admin is blocked from approving a booking request if a conflicting event exists in that slot. An admin should be able to approve high-priority clients without changing the event settings temporarily." — @scopecreepsoap (GitHub)

**Opportunity**: Advanced routing rules + priority override system.

---
Confidence
27% confidence
Finding
override system

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:24