Back to skill

Security audit

Swipenode

Security checks across malware telemetry and agentic risk

Overview

This is a real web-extraction skill, but it promotes anti-bot bypass and persistent agent integration without enough scoping or safety disclosure.

Install only if you are comfortable auditing and pinning the external source yourself. Use it only on sites you own or are authorized to access, avoid sensitive auth headers unless necessary, set clear rate limits, and review or remove any Claude Desktop MCP registration after use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README explicitly markets Cloudflare/Datadome bypass via TLS fingerprint spoofing and positions the tool for agent-driven scraping, but provides no warning about authorization, legal restrictions, rate limits, privacy, or abuse potential. In an agent skill context, this increases the chance of autonomous misuse against protected services and could facilitate unauthorized data collection or evasion of site defenses.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The README documents an auto-registration command that modifies Claude Desktop configuration but does not warn users that local config files will be changed. In an agent/tooling environment, silent or poorly disclosed configuration changes can surprise users, weaken trust boundaries, and make it easier for a skill to persist itself into local agent workflows.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list is broad and includes common terms like "scrape," "extract data," and "cloudflare," which can cause the skill to activate for many ordinary user requests. In this skill, that is more concerning because the described functionality performs live network access and includes WAF/TLS-bypass positioning, so accidental invocation could steer agents toward risky scraping behavior without clear user intent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documentation does not clearly warn that use of the binary will make outbound requests to third-party websites and transmit user-supplied URLs/data. That omission is especially risky here because the tool is marketed for scraping and Cloudflare-bypass scenarios, where users may unknowingly initiate contact with protected services and expose sensitive targets, prompts, or identifiers through network activity.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.