Back to skill

Security audit

whydoesmysitesuck.com — website quality scores

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed website-scoring integration that calls an external audit API; the main caution is to use it only for domains the user owns or is authorized to assess.

Before installing, understand that using this skill sends the target domain to whydoesmysitesuck.com and may trigger a live crawl. Use it only for domains you own or are authorized to assess, and provide your own email only if you want to register for the API key.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description contains broad trigger phrases such as 'audit this website', 'score this domain', and 'how good is example.com' that are common in normal conversation and could cause the agent to invoke this skill when the user did not explicitly intend to run a live external website audit. Because the skill performs real network calls and may initiate scans against third-party domains, overbroad invocation increases the risk of unintended external actions, privacy issues, and unnecessary API usage.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.