Back to skill

Security audit

Daily Ai News

Security checks across malware telemetry and agentic risk

Overview

This skill fetches and summarizes public AI news, with only guidance-level concerns about broad activation wording and external browsing.

Install this if you want an agent to gather and summarize current AI news from public websites. Expect it to perform live web searches and fetch external articles; use care with ambiguous AI requests, and treat retrieved webpages as untrusted source material rather than instructions for the agent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description says the skill activates when the user asks for 'AI updates' or 'latest AI developments', which are relatively broad phrases and may overlap with ordinary conversation about AI rather than an explicit request for a news briefing. The trigger list does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Phrases like 'Mentions wanting to know what's happening in AI', 'AI industry news, trends, or breakthroughs', and 'summary of recent AI announcements' are broad and lack clear scope limits. Without explicit boundaries, the skill may be invoked for general AI discussion, analysis, or education requests rather than a current-news briefing.

Missing User Warnings

Low
Confidence
87% confidence
Finding
The markdown instructs the skill to use web fetching and web search across multiple external sources, but there is no user-facing warning that the skill will access external sites and retrieve content based on the user's request. For markdown skill descriptions, behaviors that may affect privacy or network activity should be disclosed clearly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.