Latchkey

Security checks across malware telemetry and agentic risk

Overview

Latchkey is a disclosed but very broad credential-injecting API tool that can let an agent act across many services, so it needs careful review before use.

Install only if you trust the latchkey npm package and explicitly want an agent to make authenticated API calls for you. Configure one narrowly scoped service at a time, prefer read-only or least-privilege tokens, avoid production/admin/payment credentials unless necessary, and require confirmation before any write, delete, billing, public-posting, or permission-changing request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill is intentionally framed for 'arbitrary' third-party and self-hosted HTTP APIs, which makes its invocation scope very broad. In an agent setting, this can cause the skill to be selected for generic web/API tasks and trigger authenticated outbound actions against many services, increasing the chance of unintended data access or side effects.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal