Security audit
Sonarbay News
Security checks across malware telemetry and agentic risk
Overview
This skill is a straightforward news-search integration, with the main caution that its optional CLI install runs a remote installer script.
Install this only if you trust SonarBay as the news provider. Before running the CLI installer, prefer downloading and reviewing the script or using the REST API fallback directly; remember that news queries sent through the CLI or API will be visible to the service.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
62/62 vendors flagged this skill as clean.
