Back to skill

Security audit

产业链上下游拓客

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Cue-based business research workflow that uses an external API and local report files in ways that fit its stated purpose.

Before installing, verify the sensedeal/cue-skills runner source, use a scoped Cue API key if available, and avoid sending confidential enterprise information unless you are comfortable sharing that query content with Cue's hosted service. Review generated reports before distributing them because the skill relies on external data sources and server-side analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs the user to run a built-in installation step and later writes output files under user-controlled directories, but it does not clearly warn that it will clone code, create files, and modify local state. This is dangerous because users may execute the workflow without understanding that it changes their filesystem and persists artifacts, increasing the chance of unintended code introduction or data exposure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill has the user read an API key from local configuration and send it to external Cue endpoints, while also transmitting query content derived from the target enterprise. Without a clear security/privacy notice, users may unknowingly disclose credentials and potentially sensitive business research inputs to a third-party service.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.