Back to skill

Security audit

Anime Download Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed anime torrent search/download helper, but users should understand the legal, privacy, and untrusted-download risks of BitTorrent before using it.

Install only if you are comfortable using BitTorrent and running the external anicatch tool through uvx or pipx. Confirm downloads explicitly, pick a safe output folder, verify that content is lawful for you to download, and treat downloaded files as untrusted until scanned or otherwise validated.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The README explicitly promotes searching and downloading anime torrents but provides no warning about legal risk, exposure of the user's IP address to torrent peers, or the possibility of downloading untrusted content. In the context of an agent skill, this omission is more dangerous because users may trigger networked download behavior through automation without understanding copyright, privacy, or malware implications.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger description is overly broad because it activates on generic requests like 'find anime resources,' which can cause the skill to engage in contexts where the user did not clearly ask for torrenting or downloads. In this skill, that broad routing is more dangerous because the actions involve piracy-adjacent search and BitTorrent download behavior, increasing the chance of unintended network and file operations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill repeatedly instructs the agent to perform torrent searches and downloads without warning about side effects such as writing files, opening network connections, contacting trackers/DHT, or potential legal and security exposure from downloaded content. In this context, the lack of user warning is especially risky because BitTorrent activity is not passive browsing; it can expose the user's IP, consume bandwidth, and retrieve untrusted files to disk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.