Back to skill

Security audit

wenwan-authentication

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent jewelry authentication guide, but it needs Review because it asks users to expose item photos via public URLs and recommends tests that could damage valuable items.

Review this skill before installing if users may appraise valuable items. Treat its outputs as preliminary, avoid posting public photos that reveal ownership or personal details, and use non-destructive checks or certified gemological testing before trying heat, scraping, burning, or purchase decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger scope is broad enough to activate for general jewelry appraisal and purchase-advice scenarios, which can cause the agent to invoke this skill outside its strongest validated domain. In context, that creates a risk of overconfident financial or authenticity guidance on high-value goods, potentially misleading users into poor purchase decisions.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs users to upload images to a public URL for analysis without warning that photos may expose personal, location, or ownership-sensitive information. In this context, users may share images of valuable items, backgrounds, metadata, or receipts, increasing privacy leakage and targeting risk if those URLs are publicly accessible.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The guide recommends destructive or potentially damaging authentication methods such as hot-needle, knife-scrape, glass-scratch, and fire testing, while only attaching brief inline cautions rather than a strong upfront warning and safer-first workflow. In this skill context, users are likely to apply the advice directly to valuable jewelry items, creating a realistic risk of damaging property, misidentifying items, or reducing resale value.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.