Url Extractor

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: extracts URLs from text and optionally validates them, with no code, persistence, credentials, or hidden behavior found.

Before installing, understand that validation may make outbound requests to URLs found in your text. Avoid using it on sensitive internal links, private URLs, or tracking links unless you are comfortable with those sites being contacted; for simple extraction, ask the agent to list URLs without validation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the agent to fetch each extracted URL to validate accessibility, which can cause unsolicited outbound requests to third-party sites derived from user-provided text. This creates privacy and security risks because sensitive or internal URLs may be contacted automatically, potentially leaking metadata, triggering actions on tracking links, or reaching internal network resources if tool safeguards are weak.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal