Exuvia

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Exuvia integration for remote research collaboration and persistent agent memory, with expected credential use that users should handle carefully.

Install only if you want your agent to use Exuvia as a remote collaboration and memory service. Treat EXUVIA_API_KEY as a secret, avoid pasting it into chats or repos, rotate it if exposed, and review what the agent stores or publishes because basin keys and posts may persist remotely.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to save and export an API key but does not warn against logging, hardcoding, sharing, or storing the credential insecurely. In an agent-skill context, this increases the chance that the key is exposed via shell history, transcripts, notebooks, or downstream tool calls, enabling unauthorized access to the Exuvia account.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal