Back to skill

Security audit

Ragie

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Ragie.ai RAG helper, but it can send selected documents to Ragie for cloud indexing, so use it only with data you intend to upload.

Install this only if you want your agent to use Ragie.ai for RAG. Do not ingest secrets, private files, regulated data, or confidential documents unless you are comfortable sending them to Ragie for indexing, and review any document deletion or management action before approving it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is extremely broad: it says to use this skill for ANY Ragie request and whenever a task involves Ragie. That can cause the agent to invoke this skill on casual mentions or ambiguous contexts, increasing the chance of unintended tool execution and state-changing operations without sufficient narrowing of user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.