Back to skill

Security audit

NLB

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow helper for the National Library Board of Singapore website, with disclosed login use and no executable install, persistence, or hidden data flow.

Install this only if you want an agent to help with your NLB account or catalogue searches. Enter credentials only on the official NLB sign-in page, do not ask the agent to store or repeat your password, and assume the agent can view loan, overdue, and recommendation information while logged in.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to log into a third-party library account using the user's myLibrary username and password, but provides no guidance on secure credential handling, consent boundaries, or avoidance of storing/seeking secrets in unsafe channels. This creates a real risk of credential exposure or misuse because the skill normalizes direct credential use for account access without privacy safeguards.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.