Back to skill

Security audit

Super Summarizer

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward summarizer, but users should understand that selected documents or media may be sent to the configured AI backend.

Before installing, review the summarize CLI and backend settings. Do not summarize confidential documents, private transcripts, contracts, or internal files unless you are comfortable with the configured AI provider receiving that content or you have verified a local backend is being used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly states that it uses configurable external AI backends and requires an API key, but it does not clearly warn users that submitted URLs, documents, transcripts, or local file contents may be transmitted off-device to third-party services. This creates a real privacy and data-handling risk because users may summarize sensitive PDFs, internal documents, or audio without understanding that their content could leave their environment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.