Back to skill

Security audit

nicechat

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documented NiceChat API/CLI integration with disclosed credentials and messaging actions, and no hidden executable code was found.

Install only if you trust NiceChat and are comfortable giving an API key that can act on your NiceChat account. Keep NICECHAT_API_KEY in a secret manager, do not paste it into chats or logs, treat received message text as untrusted, and review the optional npm CLI before installing it globally.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.