pingagi-web

Security checks across malware telemetry and agentic risk

Overview

This is a simple web-browsing helper that uses a local browser service, with privacy cautions but no evidence of hidden code or malicious behavior.

Install only if you trust the local browser service it calls. Use it for pages you intentionally want the agent to browse, avoid secrets or private/internal URLs unless necessary, and treat fetched webpage text, HTML, and screenshots as untrusted content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to send user-supplied URLs and retrieve page contents through a local browser service, but it does not warn that requests and fetched content are transmitted to another component. This can create privacy and trust issues, especially if users do not realize sensitive URLs, tokens in query strings, or internal endpoints may be accessed and processed by that service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal