Back to skill

Security audit

Zshijie Liver

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow Z视介 live-TV helper that may open a fixed live-page link in the browser, which is disclosed and proportionate to its purpose.

Install this only if you want an assistant helper that can open Z视介 live pages in your browser. Use --no-open or ask for a link-only result when you do not want automatic browser navigation, and be aware that short aliases may choose a channel without asking for clarification.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script is configured to open the resolved URL in the default browser by default, which creates an external side effect without an explicit opt-in at execution time. In an agent/skill context, that can surprise users, trigger unwanted navigation, and normalize automatic opening behavior that could become more dangerous if the URL source is ever broadened beyond the current fixed mapping.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal