Back to skill

Security audit

Web Extractor

Security checks across malware telemetry and agentic risk

Overview

This is a simple webpage text-extraction helper, but users should avoid using it with private or sensitive URLs because it routes requests through r.jina.ai.

Install this for summarizing public articles, news pages, and blogs. Do not use it with intranet links, authenticated pages, private documents, or URLs containing tokens or sensitive query parameters unless you are comfortable sharing the URL and retrieved content with r.jina.ai and temporarily storing the extracted text locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match many ordinary browsing and summarization requests, which can cause the skill to activate unexpectedly. That increases the chance that user-supplied URLs are sent to the external r.jina.ai service without clear user intent or awareness, expanding data exposure and unintended tool use.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The workflow instructs the agent to send arbitrary user-provided URLs to r.jina.ai but does not warn that page content and the target URL are being transmitted to a third-party service. This creates a meaningful privacy and data-handling risk, particularly if users provide intranet links, sensitive documents, personalized pages, or URLs containing tokens or identifiers.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.