Back to skill

Security audit

Thoth Lite

Security checks across malware telemetry and agentic risk

Overview

The skill appears to perform a user-directed documentation workflow, with a privacy caveat around exposing selected project files to the agent.

Before installing or using it, review which project files will be included and avoid pointing it at secrets, credentials, private keys, .env files, or highly confidential source unless you are comfortable with those contents being processed by the agent/documentation workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill reads and prints content from up to 20 files directly from the user-specified project path, then instructs the downstream documentation workflow to generate output from those contents. This creates a real data exposure risk because source files often contain embedded secrets, credentials, tokens, internal URLs, or proprietary code, and the skill provides no warning, filtering, or secret-redaction step before sending that material into an AI-assisted process.

VirusTotal

47/47 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.