Back to skill

Security audit

Hot Alert Cn

Security checks across malware telemetry and agentic risk

Overview

This appears to be a limited hot-topics alert helper with no evidence of network access, persistence, credential use, or harmful behavior.

This skill looks safe to install for lightweight, possibly simulated hot-topic alerts. Treat its results as sample or static unless the publisher documents real data sources, and re-review permissions if a future version adds live monitoring, scheduling, network access, or notifications.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases and described capability are broad enough to match ordinary requests about hot topics, monitoring, or alerts without clear boundaries on when this skill should activate. That can cause unintended invocation and data/context capture by the skill, especially in multi-skill environments where routing ambiguity may send user requests here instead of a more appropriate skill.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal