Back to skill

Security audit

ChatDOC Studio--KnowledgeMate

Security checks across malware telemetry and agentic risk

Overview

This skill clearly does what it says: it uploads user-selected PDF/DOC/DOCX files to ChatDOC Studio through PDRouter and manages that knowledge base.

Install only if you intend to send the selected PDF/DOC/DOCX files to ChatDOC Studio through PDRouter. Be careful with broad directories because supported files are scanned recursively and uploaded, up to the documented 300-file limit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The script reads arbitrary local PDF/DOC/DOCX files and uploads their full contents to an external service over HTTPS using a bearer token, but it provides no explicit warning, confirmation, allowlist restriction, or dry-run step before exfiltrating document data. In an agent-skill context, this is more dangerous because the tool is specifically designed for automation, so users or upstream agents may trigger uploads on sensitive local documents without fully appreciating that the data is leaving the host.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.