Back to skill

Security audit

agent-tollbooth

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only guide for safer API access patterns, with disclosed local logging/cache behavior and no bundled code that accesses credentials or runs automatically.

Install only if you want your agent to consult third-party API operating notes. Treat the authentication sections as sensitive guidance: keep credentials in secure stores, avoid logging tokens or API keys, and review any agent action that would write to business-critical services such as Ghost, Stripe, GitHub, Notion, or Airtable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
84% confidence
Finding
The file documents authentication schemes and explicitly points to where high-value secrets are stored, including the Ghost Admin API key location and format. While it does not disclose the secret itself, this materially lowers the barrier for misuse by guiding an agent or operator directly to credential sources, which is risky in a skill specifically designed to grant web access privileges.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.