Now Huatou Engine

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent, but it may send sensitive emotional or crisis-related user input to an external model routing service without clear privacy notice or user control.

Install only if you are comfortable with potentially sensitive emotional context being routed to an external model service. Avoid entering crisis details, personal identifiers, or private health information unless the publisher adds clear disclosure, opt-in, and data-minimization guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documentation specifies sending raw user input to an external model routing service, but it does not mention any notice, consent, minimization, or handling of sensitive mental-health-related content. Because users may disclose highly personal crisis or emotional information, undisclosed network transmission creates a meaningful privacy and data-governance risk even if the feature is not overtly malicious.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal