7bu uploader

Security checks across malware telemetry and agentic risk

Overview

This is a simple instruction-only uploader that sends a user-chosen image to 7bu.top using a user-provided token, with no hidden code or persistence.

Install only if you trust 7bu.top with the images you upload. Verify the exact file or URL before invoking the skill, treat the TOKEN like a password, avoid placing it in shared logs or public chats, and rotate it if it is exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger format is too loosely specified: it accepts both a local image path or a URL plus a token, without defining trust boundaries, validation rules, or exclusions. In an agent setting, this ambiguity can lead to unsafe behavior such as fetching attacker-controlled remote content, uploading unintended local files, or mishandling sensitive bearer tokens supplied in natural language.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal