Back to skill

Security audit

Legion Loan Outreach Insight

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed ASR transcript reporting helper that uses an auth token to fetch recordings, with no evidence of hidden persistence or unrelated data access.

Install only where the Legion API endpoint and JWT are intended for this use. Treat fetched transcripts, stdout, and generated reports as sensitive business/customer data, and avoid pointing LEGION_HARDWARE_BASE_URL at an untrusted host.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/fetch-asr-recordings.mjs:9