Back to skill

Security audit

tech-trending

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a trend-research helper whose API-backed script behavior fits its purpose, but users should know it may send research queries to an external service.

Install only if you are comfortable with the skill making external API calls for trend research. Avoid sending confidential business plans, private customer data, or sensitive prompts unless the publisher clearly documents the API endpoint, data handling, and retention behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger list is very broad and includes generic research phrases such as 'market research', 'trend analysis', and 'startup ideas', making accidental activation more likely in unrelated conversations. Over-broad routing can cause this skill to take over benign requests and push users toward external API/script-backed behavior they did not explicitly request.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation prominently exposes an external API base URL and instructs execution of `./scripts/trending.sh` without warning that this will make outbound network calls to a third-party service. In an agent setting, hidden or poorly disclosed network access can leak prompts, metadata, or user-driven queries to external infrastructure and expands the attack surface through remote dependencies.

VirusTotal

50/50 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.