Back to skill

Security audit

quiver-quant

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Quiver Quantitative API helper, with a minor credential-handling disclosure gap but no evidence of hidden, destructive, or unrelated behavior.

Install only if you intend to use Quiver Quantitative and have a valid API key. Treat QUIVER_API_KEY as a secret, avoid pasting it into shared shells or logs, and note that the referenced query script was not included in the inspected artifact, so the skill may not work as documented until that implementation is present.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
84% confidence
Finding
This markdown file instructs the user to export a QUIVER_API_KEY, which is a sensitive credential, but it does not include any warning about keeping the key private or that the skill will use it for outbound API requests. Under the markdown-specific missing-warning criteria, credential use and privacy-affecting network behavior should be disclosed to the user.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.