web-search

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed web-search skill that sends user-chosen searches to SkillBoss API Hub and does not show hidden persistence, destructive behavior, or unrelated access.

Install only if you are comfortable using a SkillBoss API key and sending search terms to SkillBoss API Hub. Do not submit passwords, secrets, regulated personal data, or confidential business information as queries, and treat returned web snippets and links as untrusted external content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The skill description and usage guidance are very broad, covering generic research, fact-checking, finding resources, and current information requests. Such loose activation boundaries can cause the agent to invoke this skill for many ambiguous prompts, leading to unnecessary external web queries, unintended transmission of user-provided content to a third-party API, and overuse of network/file-write capabilities in contexts where a local answer would suffice.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
User search queries are transmitted to a third-party API, but the tool does not provide an explicit disclosure at runtime that submitted queries leave the local environment. In agent settings, users may assume a local search capability, so sensitive prompts, internal project names, or proprietary terms could be unintentionally disclosed to an external service.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal