Password Manager

Security checks across malware telemetry and agentic risk

Overview

This is a plausible password-manager skill, but it handles highly sensitive credentials while leaving important storage, autofill, leak-checking, and cloud-sync details unclear.

Review carefully before using with real passwords. Confirm where passwords are stored, how the master password and encryption keys work, whether leak checks or cloud sync send password-derived data externally, and whether autofill always requires explicit user approval. Avoid entering real passwords directly as command-line arguments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises password storage, auto-fill, and leak detection but does not disclose how sensitive credentials are stored, whether leak checks send password-derived data to external services, or what sites auto-fill may target. For a password-management skill, missing privacy and transmission warnings can cause users to expose highly sensitive secrets under assumptions that may be unsafe.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal