Back to skill

Security audit

Na He

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is coherent for video motion analysis, with the main caution that it tells the agent to send results to Feishu.

Use this skill only with videos you are allowed to download or analyze. Before sending results, verify the Feishu recipient and message contents, and avoid including sensitive video details unless necessary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly sends analysis results to Feishu, an external messaging service, but provides no warning, consent step, or data-minimization guidance. Because inputs may include user-supplied video URLs, local video files, titles, timestamps, and potentially sensitive activity analysis, this can disclose private data to a third party without the user's informed approval.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.