LinkSwarm

Security checks across malware telemetry and agentic risk

Overview

LinkSwarm is a transparent API guide for a backlink exchange service, with no hidden code or local execution, but it does send site and account details to a third party.

Install only if you are comfortable letting an agent interact with a third-party backlink marketplace for domains you control. Treat the API key as sensitive, review partners, pages, anchor text, and monthly limits before allowing automated exchanges, and check LinkSwarm's privacy and removal policies for any lasting records or links.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill prominently instructs users to send email addresses, site domains, categories, page URLs, and API-authenticated requests to a third-party service without any privacy, consent, or data-sharing warning. In an agent setting, this can cause users or upstream systems to disclose operational metadata and credentials to an external network without informed approval.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal