Airops

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a legitimate AirOps integration, but it exposes broad write/delete API capabilities without clear user confirmation guardrails.

Review this skill before installing if your AirOps API token can create, update, run, retry, cancel, or delete workflows or data. Use a least-privilege token where possible, prefer read-only actions by default, and require explicit confirmation before any mutating proxy request or workflow execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill documents generic action execution and raw proxy requests, including support for POST, PUT, PATCH, and DELETE, without guardrails or warnings about remote side effects. In a data/workflow platform like AirOps, this can enable unintended modification, deletion, or triggering of workflows if an agent follows vague user requests or misinterprets available actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal