competitive-intel

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed onboarding guide for Bright Data web scraping and search tools, with no hidden code or destructive behavior found.

Install this only if you intend to use Bright Data for live web search, scraping, structured data, or app integration. Review the curl-to-bash installer choice, the OAuth/API key storage, account billing/quota implications, and whether your target sites and data uses are allowed before running collection workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill strongly instructs the agent to gather live data from third-party sites, but it does not clearly warn users up front that external web scraping and outbound data collection will occur. This can undermine informed consent, surprise users, and cause unintended transmission of user-provided targets or research queries to external services.

VirusTotal

45/45 vendors flagged this skill as clean.

View on VirusTotal