Back to skill

Security audit

Content Source To Markdown

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal content-processing skill; the main risk is user choice of third-party content, not hidden or malicious behavior.

Install only if you are comfortable sending the chosen URLs, posts, snippets, or files through the skill's processing flow. Do not submit private, confidential, copyrighted, or personal data unless you have permission and understand which external services or credentials the skill uses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Low
Confidence
88% confidence
Finding
The skill description is broad enough to invite use on many kinds of URLs, social posts, and snippets without defining clear in-scope sources or exclusions. That increases the chance the skill will be applied to sensitive, private, copyrighted, or inappropriate third-party content, causing unsafe or noncompliant handling in downstream workflows.

Missing User Warnings

Low
Confidence
92% confidence
Finding
This skill explicitly processes external URLs and social content but provides no warning about privacy, consent, copyright, platform terms, or third-party data handling. Users may therefore submit content containing personal data or restricted material, creating legal, privacy, and policy risk even if the skill itself is only reformatting content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.