Back to skill

Security audit

读书种草

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed book-marketing video planning guide that uses online research, with no evidence of hidden execution, credential access, persistence, or destructive behavior.

Before installing, understand that this skill will often perform online research about the book, screenshots, or marketing context you provide. Avoid supplying private drafts, non-public business plans, personal reading notes, or sensitive customer data unless you are comfortable with related search terms being used for web research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill repeatedly instructs the agent to proactively browse and gather external information whenever user materials are incomplete, but it does not require notifying the user that their query, uploaded details, or inferred interests may be sent to third-party sites or services. This creates a privacy and consent gap: users may reasonably expect help drafting book-marketing content without realizing the system will perform external lookups based on their inputs and context.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.