Back to skill

Security audit

Lianke Print Box

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Lianke cloud printing and scanning helper, with normal risks around device credentials and document contents.

Install only if you trust the Lianke lk-print source and the Lianke cloud service. Treat ApiKey, DeviceId, DeviceKey, printed files, scanned documents, printer IDs, and task IDs as sensitive; confirm the exact file, printer or scanner, copy count, and task before running print, scan, cancel, or delete commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to configure ApiKey, DeviceId, and DeviceKey and to submit files/URLs for remote printing and scanning, but it does not warn that these credentials are sensitive or that documents and device metadata are sent to a cloud-managed service. This creates a realistic risk of credential mishandling, accidental disclosure in logs or chats, and unintentional transmission of sensitive documents to a third-party remote system.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.