Direct Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Yandex Direct campaign-analysis helper, but users should be deliberate because it uses advertising-account credentials and broad trigger words.

Install only if you intend the agent to access Yandex Direct statistics. Prefer a least-privilege token, confirm the CLIENT_LOGIN account before use, and require explicit approval before any campaign, bid, budget, or ad changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad, generic words like 'директ', 'реклама', and 'анализ рекламы' that can easily appear in ordinary conversation and unintentionally invoke this skill. Because the skill is designed to access campaign statistics using YANDEX_TOKEN and CLIENT_LOGIN, accidental activation could expose sensitive advertising data or cause the agent to operate in a context the user did not intend.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal