Back to skill

Security audit

Polt User

Security checks across malware telemetry and agentic risk

Overview

This appears to be a documentation-style API integration skill whose external data submission is expected for its purpose, with no evidence of malicious behavior.

Before installing, treat this as an external service integration: only register or submit profile fields, links, task content, or other data you intend to send to that service, and avoid secrets, private code, internal URLs, or personal data unless that is explicitly your goal.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs agents to use a live external production server and to register, submit profile data, and later transmit submissions, but it does not clearly warn users that their data will leave the local agent environment and be sent to a third-party service. In an agent-skill context, this can lead to unintentional disclosure of user or workspace information, especially if users treat the skill as an internal capability rather than an external integration.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.