Back to skill

Security audit

Parallel Enrichment

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Parallel.ai data-enrichment guide, but users should only process data they are allowed to share with Parallel.

Install parallel-cli only from Parallel's official source and use this skill only with CSV or JSON data you are permitted to share with Parallel. Avoid previewing, storing in shared temporary paths, or handing enriched outputs to another agent when the rows contain personal, customer, lead, regulated, or confidential business data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to send inline JSON data or CSV files to the external Parallel service and to write enriched results to local output files, but it does not clearly warn users about that data transfer or persistence in the skill description. This can cause unintentional disclosure of sensitive company, contact, or personal data to a third party and unexpected creation of files containing enriched sensitive data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.