Back to skill

Security audit

elsewhere-news

Security checks across malware telemetry and agentic risk

Overview

This Elsewhere reading skill is not clearly malicious, but it asks for mutable remote instructions, persistent preference profiling, broad personal-context use, scheduled automation, and automatic public likes beyond a simple read-only browsing role.

Install only if you are comfortable with persistent local preference tracking and broad personal-context use for recommendations. Review or disable the GitHub self-update instruction, keep daily push off unless you can inspect and remove the scheduled task, and require explicit approval before the agent sends any article like to Elsewhere.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill’s manifest presents a narrow read-only browsing function, but the body expands into persistent local file creation and recurring scheduled push automation. That creates materially broader capabilities than a user would reasonably expect from 'browse and read articles and podcasts,' increasing the risk of unnoticed persistence and background behavior.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The skill silently adds write-side engagement by instructing the agent to POST likes on the user’s behalf after recommendation. That is an external state-changing action not disclosed in the read-oriented description, and it can misrepresent user intent while creating unwanted third-party interactions.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Automatically creating and maintaining TASTE.md introduces a persistent profiling store that is not necessary for basic content browsing. This expands data collection and retention beyond the stated purpose, and may capture preference history the user did not knowingly authorize.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The instruction to configure a daily 09:00 recurring task introduces unattended automation beyond a simple browsing skill. Even though it asks for user agreement, this is still a materially expanded capability that should be clearly separated from the core skill purpose because it enables periodic background actions and outbound messaging.

Context-Inappropriate Capability

Low
Confidence
88% confidence
Finding
Directing the agent to read SOUL.md, memory, and user profile broadens access to unrelated personal context beyond what is needed to fetch and summarize Elsewhere content. While framed as personalization, it increases unnecessary data exposure and the chance of over-collection.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to combine multiple persistent context sources for personalization, including preference files, identity/context documents, recent memory, and user profile data. This creates a cross-source profiling system that can aggregate sensitive behavioral inferences beyond the narrow need of browsing media content.

Ssd 3

Medium
Confidence
98% confidence
Finding
The skill requires logging every recommendation outcome and user reaction, including disinterest and no-response cases, into persistent storage. This is dangerous because it creates durable behavioral tracking and negative-inference profiling that exceeds what is needed for a simple reading assistant and may persist sensitive preference signals without meaningful consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.