Data Pipeline

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward local JavaScript data-pipeline helper with no evidence of hidden network, credential, persistence, or destructive behavior.

Install only if you want an unvetted third-party JavaScript helper for local data transformation. The main practical risk is the custom stage, validator, aggregation, or callback functions you provide, because those run as normal JavaScript in your process.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill activates on very broad data-processing terms such as data cleaning, transformation, ETL, validation, grouping, aggregation, and batch/array handling without clear boundaries or exclusions. In an agent environment, this can cause the skill to trigger in many unrelated contexts and take over handling of user requests unexpectedly, increasing the chance of unsafe tool selection, misrouting, or over-collection/manipulation of user data.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal