Back to skill

Security audit

all-in-one-domain-website-tools

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple link generator for Nameslink domain, naming, and logo tools, with minor over-activation risk from broad trigger words.

Before opening a generated link, check that the domain, keyword, or project description in the URL is what you intended to share with Nameslink. Be aware that broad words like "logo" or "contains" may cause the skill to trigger when your request is only loosely related.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger term "logo" is very broad and likely to match many ordinary user requests that are not intended to invoke this skill. That can cause unintended routing to an external logo-generation URL, creating incorrect tool activation and increasing the chance of sending user-derived content to a third-party site without clear intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger term "contains" is excessively generic and can match a wide range of unrelated requests, making accidental invocation very likely. In this skill, that is more dangerous because the skill is designed to construct outbound URLs from extracted user input, so an incorrect match can misroute the user and leak query context to an external service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.