OpenDART Disclosure

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent OpenDART lookup tool that needs an API key and stores a small public company-code cache, with no evidence of hidden or unsafe behavior.

Safe to install if you are comfortable using an OpenDART API key. Prefer setting OPENDART_API_KEY instead of passing the key on the command line, and be aware the tool caches public company-code data under ~/.cache/opendart until refreshed or deleted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
82% confidence
Finding
The skill instructs use of an API key via command-line flag or environment variable but provides no warning about secret exposure risks. Passing secrets on the command line can leak them through shell history, process listings, logs, or transcripts, which is a real but relatively limited credential-handling weakness in this context.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal