Back to skill

Security audit

Tra Cuu Phat Nguoi

Security checks across malware telemetry and agentic risk

Overview

This skill performs a disclosed Vietnam traffic-fine lookup and does not show hidden persistence, credential use, or unrelated behavior.

Install only if you are comfortable sending a license plate and vehicle type to vnetraffic.org for lookup. Avoid providing a real phone number unless necessary, and treat results as preliminary until confirmed through official CSGT or registry sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The script sends a phone number field to a third-party service at vnetraffic.org without any explicit notice, consent flow, or necessity check visible in the code. Even worse, if the user does not supply a phone number, it still transmits a hard-coded placeholder number, which indicates unnecessary sharing of personal-contact-style data to an external endpoint and creates privacy/compliance risk in a skill that handles vehicle lookup information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal