Back to skill

Security audit

waitlister

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Waitlister integration that creates hosted waitlist pages and manages signups using a user-provided API key.

Before installing, be aware that using this skill can publish a publicly reachable Waitlister landing page and send signup email addresses to Waitlister. Use an API key you control, confirm before going live, and only submit real email addresses with proper authorization or consent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill tells the agent to publish a landing page live and even to verify it by fetching the hosted URL, but it does not explicitly warn that publishing makes the content publicly reachable on a Waitlister-hosted page. In an agent setting, that omission can cause accidental public disclosure of draft marketing copy, brand assets, or other user-provided content if the agent publishes before the user understands the visibility change.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill is designed to collect signups, handle subscriber emails, and submit those emails to a third-party API, but it lacks a clear privacy/data-handling warning. This can lead an agent to process personal data without adequately informing the user that email addresses will be transmitted to Waitlister and stored there, increasing compliance and consent risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.