CurlShip Directory Submission

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple CurlShip API guide, but users should approve sharing their product URL and contact email before submission.

Install only if you are comfortable sending a product URL and contact email to CurlShip for a public listing. Confirm the exact email, URL, and tier before an agent submits or requests an upgrade, and review any badge HTML before allowing changes to your website.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users or agents to send a contact email to a third-party service but does not clearly warn that personally identifiable information is being transmitted externally or describe how that data will be used, stored, or shared. This creates a privacy and consent risk, especially if an agent submits a user's email automatically without explicit approval.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal