Drone Engineer

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed API wrapper for generating drone engineering career roadmaps, with no local access or privileged behavior.

Before installing, consider that using the roadmap endpoint may send your career history, skills, goals, timestamps, and session or user identifiers to the API operator. Share only what is needed and avoid confidential employer, project, or personal details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly collects assessment data, session metadata, and potentially identifying information such as userId, but provides no privacy notice, retention policy, or guidance on handling personal data. In a career-assessment context, this can expose sensitive profiling data and create compliance and user-trust risks if the data is logged, shared, or retained without clear disclosure.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal