Algorithmia

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Tencent Weiyun cloud-storage skill with powerful account access, but its risky actions are purpose-aligned and bounded by explicit safeguards.

Install only if you trust this skill with the Weiyun account you authenticate. Prefer a dedicated or low-risk account, avoid bypassing confirmations, name exact paths for any change, and delete cookies.json or log out of Weiyun when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill advertises destructive capabilities like deleting files and directories without any warning, confirmation requirement, or safeguard language. In an agent setting, this increases the risk of accidental or overly eager destructive actions against user data, especially because the integration can act on live remote resources.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal