Back to skill

Security audit

Okfile

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent OkFile upload/publishing helper, with the main caveat that uploaded files and sites should be treated as externally shared.

Install only if you intend to use OkFile as a third-party upload and publishing service. Treat generated file links, previews, directory listings, and site URLs as externally shareable unless OkFile separately confirms access controls, and avoid uploading secrets, private personal data, regulated data, or confidential business files. If using the optional CLI, review the PyPI package or wheel provenance and understand where it stores any API key.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is explicitly designed to upload and publish files to a third-party service, but the description does not clearly warn that resulting links and published sites may be publicly accessible. That omission can cause users or agents to transmit sensitive files under the mistaken assumption that sharing is private or access-controlled.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The anonymous mode section encourages publishing without login but does not explicitly state that content may be publicly exposed without authentication. In a skill whose core function is external publication, this materially increases the risk of accidental disclosure of sensitive data.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.