Back to skill

Security audit

Ntriq X402 Pii Detect

Security checks across malware telemetry and agentic risk

Overview

This is a simple paid remote PII-checking API description, with the main risk being that submitted text may contain sensitive data and is sent to the provider.

Install only if you are comfortable sending the text you analyze to x402.ntriq.co.kr and paying $0.02 USDC per call. Avoid submitting regulated, confidential, or unnecessary personal data unless you have reviewed the provider's privacy, retention, and compliance terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill sends arbitrary user-provided text to a remote third-party endpoint for PII analysis, but the description does not clearly warn users that sensitive content will leave their environment. Because the very purpose of the skill is to process emails, phone numbers, SSNs, addresses, and similar data, omission of an explicit transmission warning materially increases the risk of unintended disclosure and non-compliant handling of regulated data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.