Ab Test

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a straightforward A/B testing or marketing-operations helper, with no evidence of hidden code or malicious behavior, but users should handle its API key carefully.

Install this only if you intend to let an agent help with A/B testing or marketing operations. Store the API key in a protected environment variable or secret manager, avoid pasting it into chat or committing it to files, and review any proposed experiment changes before allowing the agent to apply them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill's activation guidance is very broad ('testing related functionality', 'Automating ab tasks', 'Marketing operations'), which can cause the agent to invoke this skill for generic requests outside its intended scope. Over-broad triggering increases the chance of unnecessary execution, accidental use of configured credentials, or inappropriate delegation to scripts that act on marketing/testing systems.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation instructs users to export an API key but provides no warning about protecting, scoping, or avoiding exposure of that credential. In agent and automation contexts, missing credential-handling guidance can lead to secrets being hardcoded, logged, echoed in terminal history, or shared in outputs, increasing the risk of account compromise.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal