Gemini Citation

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Gemini-based research helper that sends user queries to Google's Gemini API for search-grounded cited answers.

Install only if you are comfortable sending research prompts to Google/Gemini and using a Gemini API key. Avoid entering secrets, personal data, proprietary material, or regulated information, and manually verify important claims against the returned source URLs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description is broad enough to match generic research or factual-summary requests, which can cause the skill to be invoked in contexts where users did not intend their prompts to be sent to an external provider. Because this skill performs live web-grounded API queries, overbroad routing increases the chance of unnecessary data disclosure and unexpected external transmission.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill documentation does not clearly warn users that their research queries are transmitted to the Gemini API and may trigger live Google Search grounding. Without a prominent disclosure, users may submit sensitive, proprietary, or personal information under the mistaken assumption that processing is local or self-contained.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal