TopHotCN

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed public hot-list and article crawler, with the main caution that it can modify JSON files you point it at.

Before installing, be comfortable with the Python and Playwright dependencies. When fetching article content, use --output or keep backups if you do not want the original JSON files changed, and only run directory mode on folders you intend to update.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly documents a mode that rewrites existing JSON files in place by filling the content field and adding metadata, but it does not prominently warn the user that original files will be modified. In an agent setting, this can lead to unintended data loss, corruption of curated datasets, or silent overwriting of prior content when the user may have expected a read-only fetch operation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal