Weibo Hot Search

Security checks across malware telemetry and agentic risk

Overview

The skill’s main purpose is understandable, but it tells the agent to kill Chrome or Edge debugging processes without asking, which can disrupt unrelated browser work.

Review before installing. The skill should be changed to prompt before terminating any browser process, use an isolated profile and random/free debug port, and only clean up processes it started. Also verify the missing scripts/weibo-hot-search.ts is supplied before expecting it to run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to automatically kill Chrome/Edge processes matching a remote-debugging pattern and retry without asking the user. Unprompted termination of user or system browser processes is a risky side effect: it can disrupt unrelated sessions, cause data loss in open tabs, and interfere with other tools using CDP on the same machine.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal