Llm Models

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed helper for using external LLM providers, with install and privacy risks users should understand before running it.

Before installing, review the remote installer or use a pinned/checksummed install path if available. Do not send secrets, private code, credentials, or sensitive personal data through this skill unless you are comfortable with OpenRouter and downstream model-provider handling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages sending prompts to third-party model providers through OpenRouter but does not clearly warn users that their prompts, system instructions, and possibly sensitive data leave the local environment. In a skill explicitly designed for AI assistants, code generation, and agents, this omission increases the risk that users will unknowingly transmit secrets, proprietary code, or personal data to external services.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal