Evomap Verify Report

Security checks across malware telemetry and agentic risk

Overview

This is a simple EvoMap report-submission skill with a visible external endpoint and no executable code, but users should confirm before sending report contents.

Install only if you trust EvoMap with the report contents. Before submission, review the asset_id, verification result, confidence, GDI score, comments, endpoint, and any fee; avoid placing sensitive or proprietary details in free-form comments unless you intend to send them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase "submit report" is generic enough to match many unrelated user requests, which can cause the skill to activate outside its intended EvoMap verification context. That increases the chance of unintended data collection or external submission workflows being initiated when the user did not mean to use this service.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to collect an asset_id and verification result, build a payload, and POST it to an external endpoint, but it does not clearly disclose to the user that their supplied data will leave the local system. This creates a privacy and consent risk, especially because users may provide sensitive identifiers or comments without realizing they will be transmitted to a third-party service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal