Back to skill

Security audit

Ask a Human

Security checks across malware telemetry and agentic risk

Overview

The skill is openly designed to send questions to random outside humans, but its examples and instructions do not adequately limit sensitive user, business, or security information from being shared.

Install only if you are comfortable with submitted prompts leaving your environment and being read by unknown human reviewers. Do not send secrets, personal data, customer/client details, private source code, vulnerability findings, internal strategy, or regulated information unless you have explicit approval and have reduced the prompt to a sanitized summary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README explicitly encourages sending agent-provided questions to a pool of random anonymous humans, but it does not prominently warn that any included prompt content may expose sensitive user data, internal context, secrets, or personal information to third parties. In an agent setting, operators may treat this as a normal helper skill and inadvertently disclose private or regulated data to unvetted humans, creating a real confidentiality and privacy risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill routes prompts to an external service backed by random humans, but the top-level description does not prominently warn that user content may be disclosed outside the system. That omission increases the chance an agent or operator will send sensitive prompts under the mistaken assumption this is a normal internal tool.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The example sends substantive user/work content to an external human-review service, including client communications context, without any notice about data sharing, consent, redaction, or suitability checks. This is dangerous because users and integrators may copy the pattern directly and unintentionally disclose confidential business information to third parties.

Missing User Warnings

High
Confidence
99% confidence
Finding
This example shares details of an authentication code review issue with random external humans, including a specific password-storage weakness and team-context details, without caution about confidentiality or secure review boundaries. That creates a real risk of leaking sensitive security information about internal systems or vulnerabilities to untrusted third parties, which could aid attackers or violate internal disclosure policies.

Ssd 3

Medium
Confidence
96% confidence
Finding
Telling the agent that responders have no context beyond what is provided and to write self-contained questions encourages copying full user/task context into prompts. In this skill's context, that means potentially exposing private conversations, proprietary information, credentials, or regulated data to random humans outside the trust boundary.

Ssd 3

Medium
Confidence
97% confidence
Finding
The parameter guidance explicitly says the prompt should include all necessary context, which operationally nudges agents to transmit raw natural-language context to outside human reviewers. Because the service is explicitly a pool of random strangers, this creates a direct risk of sensitive data leakage through prompt contents.

Ssd 3

Low
Confidence
78% confidence
Finding
The examples normalize storing question details in memory, which may retain user-derived content longer than needed and expand exposure if memory is logged, synced, or later reused. While less severe than external disclosure, unnecessary retention can compound privacy risk, especially when the stored question contains sensitive context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.