Back to skill

Security audit

Neckr0ik Automation Templates

Security checks across malware telemetry and agentic risk

Overview

This skill provides automation workflow templates and does not show hidden execution, exfiltration, or destructive behavior.

Before installing or using these templates, review each generated workflow node by node, use test data and least-privilege credentials, confirm webhook URLs, CRM targets, Slack channels, and email recipients, and only activate workflows after verifying their external effects and rollback plan.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The template format and examples normalize use of API keys, webhook URLs, CRM integrations, cloud backups, and data sync flows, but provide no warnings about handling secrets, personal data, or unintended outbound data transfer. That omission increases the chance that users will paste live credentials into templates and deploy automations that expose sensitive business or customer data.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The usage examples repeatedly tell users to configure providers, destinations, and credentials and then 'Activate' the workflow, but omit a testing or approval step before enabling live automation. In this context, immediate activation can trigger unintended emails, CRM writes, notifications, backups, or data sync operations against production systems.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.