Yandex Tracker

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Yandex Tracker integration, but it gives an agent broad ability to change or delete tracker data without built-in safeguards.

Install only if you want an agent to act in Yandex Tracker with your account's permissions. Use a least-privilege or short-lived token, avoid broad production access where possible, and require the agent to show the exact issues, comments, attachments, links, or worklogs before any delete, move, transition, or bulk update.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill explicitly documents destructive actions such as deleting comments, attachments, links, worklogs, and performing bulk changes without requiring confirmation or warning about irreversible effects. In an agent setting, this raises the risk of accidental or prompt-induced destructive operations against production Tracker data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal