Ntriq X402 Document Intel Batch

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a purpose-aligned remote document processing integration, but users should treat submitted document URLs and extracted text as sensitive data sent to a third-party service.

Install only if you are comfortable sending the referenced documents, images, and extracted text to the provider's remote service. Avoid confidential, regulated, identity, legal, medical, financial, or business-sensitive documents unless you have reviewed the provider's privacy, retention, and deletion terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to send document image URLs and receive extracted document contents from a remote endpoint, but it does not warn that potentially sensitive documents and derived text may be transmitted to and processed by a third-party service. Because the content includes OCR, classification, extraction, and summarization of up to 500 documents, users could inadvertently expose contracts, reports, IDs, or regulated data without understanding the privacy implications.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal