Back to skill

Security audit

Nox Influencer - Creator Discovery & Influencer Marketing

Security checks across malware telemetry and agentic risk

Overview

This skill is a broad but coherent NoxInfluencer marketing-operations helper with disclosed approval gates for sensitive actions.

Install only if you intend to let the agent operate your NoxInfluencer account. Review email/message sends, CRM or campaign changes, exports, contact retrieval, unlocks, and file uploads before approving them, and confirm any Chinese-site routing before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest description is extremely broad and covers creator research, outreach, CRM, monitoring, files, exports, and account setup. Such wide activation language can cause the skill to trigger for many generic marketing or operations requests, increasing the chance the agent invokes a high-privilege workflow when the user did not clearly intend to use this tool.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The skill documents a locale-routing switch that changes all URLs to the Chinese site via `--lang zh`, but it does not require explicit user consent before changing routing behavior. In a security-sensitive workflow, silent locale or endpoint changes can confuse users, alter data-handling expectations, or direct them to a different regional service boundary than intended.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.