R4

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate R4 integration, but it gives an agent broad secret access and live domain/DNS control without enough explicit user-control safeguards.

Review carefully before installing. Use this only with an R4 vault and domain account you are comfortable exposing to the agent, prefer scoped or temporary secrets, and require manual confirmation before listing secrets, running commands with injected secrets, purchasing domains, or changing DNS records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill provides direct instructions for purchasing a domain, a billable and effectively irreversible action, without requiring explicit user confirmation at execution time. In an autonomous-agent context, this increases the risk of unauthorized spending, unintended registrations, or abuse if the agent acts on ambiguous prompts.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The DNS modification example enables live infrastructure changes without warning about service impact or requiring confirmation. In practice, an autonomous agent could disrupt websites, email routing, or verification flows by altering records based on incomplete or mistaken instructions.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal