Back to skill

Security audit

Pallio AI

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill connects the user to Pallio’s hosted chat service, with the main privacy consideration that prompts and chat history are sent to Pallio.

Install this only if you are comfortable sending Pallio chat prompts and the relevant chat history to Pallio’s hosted service. Avoid entering secrets, regulated data, or sensitive personal information unless you trust Pallio’s handling of that content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs sending the user's message and full conversation history to an external third-party service, but it does not warn users that their prompts and prior messages will leave the local agent environment. This creates a real privacy and data-handling risk because users may unknowingly submit sensitive, regulated, or proprietary information to Pallio.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal