Back to skill

Security audit

Alter Actions

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Alter macOS action catalog with no hidden executable code in the reviewed artifact, though users should be careful about selected text or files being processed by Alter.

Install only if you use and trust the Alter macOS app. Before triggering actions, assume selected text or files in Alter may be sent into Alter’s processing flow, including AI or web-enabled actions, and avoid selecting secrets or confidential material. Review any separately obtained index.js helper before running it, because it is referenced by the documentation but not included in the reviewed artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly notes that Alter actions can operate on currently selected text/files and are triggered via x-callback URLs, but the user-facing description and quick-start guidance do not warn that invoking an action may send selected content into Alter for processing. This can lead to unintended disclosure of sensitive clipboard/selection/file contents, especially because the skill is user-invocable and supports broad actions like web search, summarization, email, and code operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.