TPVL
Security checks across malware telemetry and agentic risk
Overview
This is a straightforward TPVL sports lookup skill that fetches public volleyball pages and briefly caches results locally.
Reasonable to install. Running it will contact tpvl.tw, may install the listed Python packages through uv, and will write cached public sports data under /tmp/tpvl_cache. It should not need OAuth, API keys, or private credentials; do not provide secrets if prompted by anything outside these artifacts.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
