Back to skill

Security audit

LinkSwarm

Security checks across malware telemetry and agentic risk

Overview

LinkSwarm is a clear API guide for a backlink exchange service, with expected third-party data sharing but no hidden code or local execution.

Install only if you are comfortable letting an agent interact with a third-party backlink exchange for domains you control. Treat the API key as sensitive, review requested links and contributed pages before automation, and check LinkSwarm's privacy, retention, billing, and removal policies for external records and backlinks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs agents to send email addresses, domains, site names, categories, and link exchange metadata to a third-party API, but it provides no privacy notice, data handling disclosure, or user-consent guidance. In an agent setting, this is dangerous because an automated system may transmit organizational or user-owned site information off-platform without the operator clearly understanding what is being shared or how it will be retained and used.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.