Back to skill

Security audit

Swiss Geo & Tourism Assistant

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only Swiss maps and tourism helper that uses disclosed public lookup APIs, with no hidden code, persistence, or destructive behavior.

Reasonable to install for Swiss maps, tourism, transit, weather, and POI lookups. Avoid entering sensitive private addresses or detailed travel plans unless you are comfortable sending them to the listed external APIs, and verify safety-critical weather, avalanche, flood, or hiking information with official sources before relying on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
The skill introduces use of a credentialed third-party API via an environment-backed API key that is not disclosed in the manifest. Hidden credentialed egress increases the chance of unintended secret use, policy bypass, or unexpected data sharing with an external service when the user only expects public geo/POI lookups.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.