Kimi

Security checks across malware telemetry and agentic risk

Overview

This instruction-only Kimi API helper is coherent and disclosed, with expected external API use and optional local notes gated by user approval.

Install only if you are comfortable using a Moonshot API key and sending approved prompt content to Moonshot. Keep the key in environment variables, redact sensitive data before API calls, and review any saved ~/kimi/ approval or routing notes periodically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The setup instructs the agent to offer activation on broad phrases like "mention Kimi, Moonshot, long-context analysis, or Kimi-based coding," which can cause the skill to trigger in conversations where the user did not explicitly request this capability. That creates a scope-expansion risk: the skill may collect preferences, influence routing decisions, or prompt for file writes in contexts that only loosely relate to Kimi, increasing the chance of unintended persistence or external-provider handling.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal