VoteShip

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate VoteShip admin skill, but it gives an agent API-key-backed authority to change and delete project data without clear guardrails.

Install only if you trust the publisher and intend to let the agent administer VoteShip data. Use a least-privilege API key if possible, avoid handing it production authority by default, and require explicit confirmation before any update, sync, configuration, or delete action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly advertises API-key-backed admin operations that can modify project state and send data to external VoteShip services, but it does not clearly warn the user that invoking these tools may transmit potentially sensitive business/customer data or make account-level changes. In an agent setting, that omission increases the chance of unintended writes, data disclosure, or risky automation using a highly privileged credential.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The documented admin capabilities include delete operations on feature requests without an explicit caution that such changes may be irreversible or operationally significant. In a tool-using agent context, presenting destructive actions as routine functionality without guardrails makes accidental deletion or unauthorized workflow disruption more likely.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal