Rental

Security checks across malware telemetry and agentic risk

Overview

This rental helper is safe to install, but users should be careful when filling templates with addresses, entry codes, Wi-Fi passwords, or applicant documents.

Install is reasonable for rental advice and drafting. Before using generated templates, avoid posting or sending full addresses, lockbox codes, Wi-Fi passwords, bank statements, IDs, credit reports, or background-check details unless necessary and only through trusted channels. Landlords should obtain required consent, follow fair-housing and consumer-reporting rules, and delete sensitive applicant data when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The booking confirmation template explicitly includes placeholders for a full address and lockbox code/key pickup instructions, which are sensitive physical access details. In a rental skill, users may copy these templates verbatim into insecure channels or send them too early or to the wrong recipient, increasing the risk of unauthorized property access or targeted social engineering.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The pre-arrival template normalizes sharing a WiFi password, detailed access instructions, and an emergency phone number in one message without any guidance on secure delivery or recipient verification. If mishandled, this bundles enough information for unauthorized entry, privacy compromise, or follow-on abuse against the host or property.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal