Ucloud Api Skill

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real UCloud deployment skill, but its broad activation wording and plaintext credential handling make it something users should review carefully before installing.

Install only if you explicitly want this agent to operate real UCloud resources. Confirm region, resource names, costs, firewall exposure, and teardown steps before use, and avoid letting it print passwords or keys in chat; prefer scoped credentials, SSH keys, and a secure secret-delivery path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The top-level skill description is broad enough to capture generic deployment and hosting requests, which can cause the agent to invoke real cloud-operation tooling in situations where a safer, narrower skill would be more appropriate. In an agentic environment, over-broad routing increases the chance of unintended live infrastructure changes, especially when the user intent is underspecified.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The 'strong trigger' language expands the skill to many common phrases like deploying a web app, going live, or opening public access, even when the user did not explicitly ask for UCloud account actions. This makes misrouting more likely and is dangerous in this context because the skill is designed to perform real cloud changes, including provisioning and network exposure.

Missing User Warnings

High
Confidence
98% confidence
Finding
The instruction explicitly tells the agent to display login credentials after creating cloud resources, which can expose newly generated secrets in chat transcripts, logs, screenshots, or downstream tool outputs. In a cloud operations skill, these credentials may grant immediate access to compute instances or services, making the issue materially dangerous rather than merely informational.

Ssd 3

Medium
Confidence
97% confidence
Finding
Showing generated login credentials in normal workflow output creates a direct secret-disclosure path, especially because agent responses are often persisted in conversation history and operational logs. Given this skill performs real UCloud resource provisioning, leaked credentials could enable unauthorized access to freshly created infrastructure and facilitate lateral movement or service compromise.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal