全网热点聚合

Security checks across malware telemetry and agentic risk

Overview

This skill gathers public trending news, formats a short report, and explicitly sends that report to Feishu.

Install only if you want the generated hot-news brief sent to a Feishu channel. Confirm the destination channel is appropriate for your workspace, and use an environment where scraping public trending pages and sending outbound messages is permitted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to send aggregated output to Feishu, but does not warn the user that collected data will be transmitted to an external service. Even if the content is 'news,' the output may still contain sensitive derived summaries, user-request context, or organization-specific usage patterns, and silent exfiltration to a third-party channel violates least surprise and safe disclosure expectations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal