Vlog

Security checks across malware telemetry and agentic risk

Overview

This skill is instruction-only and does not request system access, but its travel-service claims do not match its vlog-editing description.

Install only if you want general travel or vlog-related prompt guidance. Do not rely on it for real-time ticket availability, flight status, visas, weather alerts, check-in, or boarding-pass information unless the agent separately verifies those details through official travel providers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill metadata claims the skill provides travel-video editing and filming tips, but the body defines travel booking, flight status, weather, visa, and boarding-pass functionality. This scope mismatch can cause the agent to route users into a skill they did not intend to invoke and may misrepresent access to real-time travel services, creating a deceptive capability boundary and increasing the chance of unsafe tool selection or user confusion.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example invocations are generic enough to match broad travel-information requests rather than a tightly scoped skill action. Overbroad triggers can cause inappropriate activation, letting the skill intercept unrelated user queries and potentially provide responses outside its declared purpose.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal