Back to skill

Security audit

Parallel Deep Research

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill appears coherent for using Parallel's external research service, with ordinary privacy and account-use cautions.

Install this only if you intend to use Parallel for deep research. Use the official parallel-cli, confirm it is authenticated to the intended account, consider quota or billing impact for high-depth runs, and avoid sending secrets, regulated data, or confidential business material unless you are comfortable with Parallel processing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill explicitly routes user research queries and retrieved context to the external Parallel API, but the documentation does not clearly warn users that potentially sensitive prompts, attached context, and resulting data will leave the local environment. In a research workflow, users may include confidential business plans, due-diligence notes, internal URLs, or regulated data, so the lack of an explicit privacy/transmission warning can cause unintended disclosure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.