Back to skill

Security audit

Breesy Restoration Connect

Security checks across malware telemetry and agentic risk

Overview

This skill submits customer-approved restoration service requests and its data sharing is disclosed, purpose-aligned, and limited to the service request workflow.

Install only if you are comfortable using it to submit restoration requests to Breesy Restoration Connect and its partners. Before submitting, confirm the customer agrees to be contacted and verify the phone number, location, service type, urgency, and damage details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to send customer contact information and incident details to an external endpoint while explicitly stating that authentication is not required, but it does not warn the user that their data will be transmitted to a third party under those conditions. In a restoration-services context, the payload is likely to contain sensitive personal and location data, so lack of transparency can lead to unauthorized disclosure or submission of private information without meaningful informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.