Incident.io

Security checks across malware telemetry and agentic risk

Overview

This documentation-only incident.io helper can change live incidents with an API key, but that behavior is visible and matches its stated purpose.

Install only if you intend to let an agent work with incident.io. Use a least-privilege INCIDENTIO_API_KEY, protect it like a password, prefer test mode or a non-production setup first, and require explicit confirmation before creating, editing, closing, escalating, or posting updates to real incidents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs users to export and use a bearer API key but does not warn that the key grants access to potentially sensitive organization incident data and should be protected from logs, shell history, screenshots, or accidental sharing. In a skill designed for agent use, missing credential-handling guidance increases the risk of inadvertent exposure or misuse of a privileged token.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document provides create, edit, close, and update workflows against live incident records without an explicit warning that these actions are state-changing and may notify responders or alter production incident management. That omission is risky because users or agents may execute examples assuming they are read-only, causing operational disruption or false incident activity.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal