OTPly

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only API skill for an email OTP service, with expected sensitive credential and OTP handling but no hidden execution or destructive behavior found.

Install only if you trust the OTPLY/ToolWeb provider for authentication-related workflows. Keep API secrets out of client-side code, chats, logs, screenshots, and repositories, and require explicit confirmation before sending OTPs to recipients.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The documentation instructs users to place both an API key and API secret directly in request headers, but provides no warning about secure handling, storage, redaction, or avoiding exposure in logs, client-side code, or shared examples. This increases the risk that integrators will embed long-lived secrets in unsafe locations or accidentally leak them through screenshots, repos, telemetry, or browser-based requests.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal