Back to skill

Security audit

Cloud Service Mapper & Decision Advisor

Security checks across malware telemetry and agentic risk

Overview

This is a cloud recommendation API skill that does not install code, but users should avoid submitting confidential infrastructure details unless they trust the provider.

Before using this skill, verify the ToolWeb/API operator and avoid sending secrets, exact internal architecture, compliance-sensitive details, or confidential migration plans. Use pseudonymous session and user identifiers where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly documents collection of sessionId, userId, and timestamp for tracking, audit, multi-tenant tracking, and personalization, but provides no notice about data handling, retention, sharing, or privacy safeguards. In a cloud advisory skill, these identifiers can enable user correlation and behavioral tracking across requests, creating privacy and compliance risk even if they are not highly sensitive on their own.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The request schema explicitly collects sessionId, optional userId, and timestamp, which are potentially identifying or linkable metadata, but the spec provides no notice, minimization rationale, or privacy guidance. In an AI skill context, this increases the risk of unnecessary transmission, retention, or downstream logging of user-linked data across cloud analysis workflows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.