Back to skill

Security audit

Dropage Deploy

Security checks across malware telemetry and agentic risk

Overview

This skill transparently uploads a user-selected HTML file or supported archive to Dropage and returns a temporary public link.

Install this only if you want an agent to publish selected HTML files or site archives to dropage.online. Review files first and avoid confidential pages, embedded secrets, internal documents, private assets, or anything you do not intend to make publicly accessible, even temporarily.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match common requests like 'share this HTML' or 'get a link', which can cause the skill to activate when a user did not explicitly intend to publish content to a public internet service. In this skill's context, unintended invocation is more dangerous because activation leads directly to third-party upload and public URL creation, creating privacy and data exposure risk.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs uploading user files to dropage.online and returning a public URL, but the description does not prominently warn that this is a public third-party hosting action. In context, this is especially risky because users may provide sensitive HTML bundles, archives, or embedded assets assuming ordinary file handling rather than external publication.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.