Back to skill

Security audit

Anyone Procotol Proxy

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward proxy skill that discloses its network-routing purpose, with risks users should understand before enabling it.

Install only if you intentionally want selected traffic routed through the Anyone Network. Verify the npm package and publisher before using the global install command, avoid proxying secrets or regulated/internal data unless your policy allows it, and stop the proxy when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to start a local anonymity proxy and route requests to external services, but it does not provide a clear warning about the security, compliance, and attribution implications of masking network origin or contacting third-party endpoints. In an agent context, this omission can mislead users into enabling anonymous outbound traffic without understanding that requests may bypass normal monitoring expectations or reach hidden/external services.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.