Back to skill

Security audit

API / Application Programming Interface

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only API reference skill that discloses its external-service examples and local preference storage, with no evidence that it runs calls, collects secrets, or hides behavior.

Install this as an API documentation aid, not as an automation that should run commands unattended. Treat any generated POST/PATCH/DELETE/payment/message examples as live-impacting unless you are using sandbox credentials, and avoid putting real secrets, customer data, transcripts, or regulated content into copied examples without authorization.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (22)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The examples explicitly send prompts, images, and audio to external AI services but provide no warning that user content will leave the local environment and be processed by third parties. In a skill intended to help users integrate APIs, this omission can lead to accidental disclosure of sensitive or regulated data because users may copy examples directly without considering privacy, consent, retention, or data-handling implications.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The file contains numerous example requests that transmit user identifiers, emails, behavioral events, profile traits, and operational telemetry to third-party analytics platforms without any privacy, consent, environment-safety, or production-impact warnings. In a skill explicitly designed to help users integrate external APIs, these examples are likely to be copied directly, so omission of warnings can lead to unintended disclosure of personal or sensitive operational data to real vendors.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The examples include state-changing or destructive operations such as resolving Sentry issues and deleting Algolia objects, but do not warn that executing them can alter production state or remove data. Because this skill is a copy-paste reference for live third-party APIs, users may run these commands against real environments and unintentionally modify incident workflows or delete indexed content.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The file provides ready-to-run examples for sending SMS, emails, calls, chat messages, and file uploads to third-party services, but does not include any warning about transmitting personal, confidential, or regulated data to external platforms. In an agent skill, this omission can normalize unsafe data handling and increase the chance that users or downstream agents send sensitive content, recipient details, or documents to external services without consent, minimization, or policy checks.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation includes create, update, and delete CRM examples that can modify or remove live customer records, but it does not warn users that these are destructive operations. In an agent skill context, examples are often copied verbatim, so omission of caution increases the chance of accidental data loss or unauthorized changes in production systems.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The examples demonstrate querying and retrieving CRM contacts and related fields such as names and email addresses without any privacy or least-privilege warning. Because CRM data frequently contains regulated or confidential personal data, normalizing broad retrieval patterns can lead to over-collection, accidental disclosure, or misuse when operators reuse the examples in real environments.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill documents how to retrieve Gong call transcripts without warning that transcripts may contain highly sensitive conversation content, personal data, confidential business information, or regulated communications. In an agent workflow, this materially raises the risk of privacy breaches and inappropriate downstream use because transcript extraction is presented as routine.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The examples use high-privilege credentials such as `SUPABASE_KEY` in both `apikey` and `Authorization` headers without a clear warning to avoid exposing service-role secrets in client-side contexts. In this skill context, users may copy-paste examples directly, which increases the chance of credential leakage or overprivileged integration patterns.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The auth examples include plaintext email/password requests using realistic credential shapes but provide no caution about handling real credentials, secret storage, or safe testing practices. In an API troubleshooting skill, users are especially likely to reuse production credentials while debugging, increasing the risk of accidental exposure in logs, terminals, or shared snippets.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
These sections include infrastructure and access-management actions such as creating clusters, branches, passwords, users, and access-list entries without warning about cost, privilege, or exposure consequences. Because the skill is intended for direct API integration and debugging, operators may execute examples against production systems, leading to accidental resource creation, public exposure, or unauthorized access expansion.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The examples instruct users to place the OpenWeather API key in the URL query string, which is commonly logged by shells, proxies, browser history, analytics, and server access logs. Even though some third-party APIs support query-parameter authentication, documenting it without any warning or safer alternatives increases the chance of accidental credential exposure.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The Mapbox examples embed the access token directly in request URLs without warning that URLs are high-exposure surfaces. This is especially risky because these examples may be copied into browsers, logs, bug reports, telemetry, or frontend code, causing token leakage and unauthorized API usage.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The Google Maps examples place the API key in the URL and do not warn that query parameters may be captured in logs, browser history, monitoring tools, and intermediary systems. Because users often copy these examples verbatim, the documentation can normalize insecure handling of credentials and lead to quota theft or unauthorized billing.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The example includes a destructive customer-deletion operation without any caution, confirmation guidance, or warning about irreversible privacy/data-loss consequences. In an API reference skill, such examples can be copied directly into production workflows and may lead to accidental deletion of user records or misuse in bulk operations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The file documents payment creation, subscriptions, invoices, and refunds without an explicit warning that these actions can trigger real charges, refunds, or customer/account changes when used against live credentials. In an agent skill that helps users call third-party APIs, omission of such guardrails increases the chance of accidental real-money or account-impacting operations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The authentication examples show secret keys and bearer tokens directly in curl commands without warning that command history, logs, screenshots, or copied snippets can expose credentials. In a skill intended to guide API usage, this can normalize unsafe secret handling and lead to credential leakage.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file contains numerous example commands that create, update, delete, cancel, or otherwise modify third-party resources across many SaaS platforms, but it provides little or no warning that these examples are state-changing. In an agent skill context, users or downstream agents may copy or execute examples directly against live accounts, causing unintended data loss, record changes, event cancellations, uploads, or task/status mutations.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The document includes numerous live API examples that send bearer tokens or OAuth credentials and perform state-changing actions such as posting tweets, LinkedIn shares, Instagram publishing, Reddit submissions, and Twitch chat messages. In a skill intended to help users call third-party APIs, the lack of explicit warnings about using real credentials, redacting tokens, and avoiding production/live accounts increases the risk of accidental credential exposure or unintended actions on real social accounts.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The Intercom section includes live write examples that create contacts, reply to conversations, and send messages without any warning that these actions modify production customer data or can send outbound communications. In an API troubleshooting skill, users may copy-paste examples directly, making unintended writes to real support systems plausible.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The Zendesk examples create and update tickets, including a public comment, but do not disclose that running them can alter live support records and publish visible customer replies. Because this skill is designed for operational API use, omitted warnings materially increase the risk of accidental production actions.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The Freshdesk examples perform ticket creation and replies without warning that they can change ticket state and send communications to customers. In support tooling, accidental execution can create operational noise, confuse customers, and expose internal troubleshooting activity externally.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The Help Scout examples create conversations and send replies but do not warn that these are outbound customer-facing actions in a live mailbox. Users troubleshooting APIs may execute the snippets as-is, causing unintended customer contact and pollution of support history.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
apis/media.md:208

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
apis/payments.md:423

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
apis/realtime.md:464