Kmoe Manga Download

Security checks across malware telemetry and agentic risk

Overview

This is a coherent manga downloader skill, but users should be careful with credentials and optional callback commands.

Install only if you trust the external kmoe-manga-downloader pip package. Prefer entering passwords through the interactive prompt instead of using -p on the command line, use only accounts you are authorized to use, choose a limited download folder, and approve callback commands only when you understand exactly what they will execute.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly documents passing a password on the command line (`-p <password>`) and discusses credential pool management without any warning about secure handling. Command-line passwords can be exposed through shell history, process listings, logs, or shared terminal recordings, making credential leakage a realistic risk in normal use.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill promotes post-download callbacks via a shell command string without warning that the callback executes arbitrary commands and can modify files or system state. Because callback templates interpolate book and volume metadata into a shell command, unsafe usage can lead to command injection or unintended execution if metadata contains shell-special characters or if users reuse the pattern with more sensitive commands.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal