Satellite Comm

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward external API skill for generating a satellite communications career roadmap, but users should treat submitted career details as shared with a third-party service.

Before using this skill, assume your career history, education, skills, goals, session IDs, timestamps, and any user ID are sent to an external provider. Avoid sending sensitive personal details that are not necessary, and review the provider's privacy and retention practices before using it with real users or organizational data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly collects assessment details, session identifiers, timestamps, and optionally a user ID, but provides no privacy notice, retention limits, consent guidance, or data-handling constraints. This creates a real privacy and compliance risk because users may disclose identifiable career-profile data to a third-party service without being informed how it is stored, shared, or protected.

External Transmission

Medium
Category
Data Exfiltration
Content
## References

- **Kong Route:** https://api.mkkpro.com/career/satellite-comm
- **API Docs:** https://api.mkkpro.com:8072/docs
Confidence
79% confidence
Finding
https://api.mkkpro.com/

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal