Back to skill

Security audit

nicebox-site-manager

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward NiceBox API helper, with normal cautions around live publishing and private message data.

Install this only if you want an agent to manage your NiceBox site. Keep AIBOX_API_KEY private, avoid overriding the base URL unless you trust the destination, review articles before publishing, and treat listed messages or leads as sensitive data that should not be shared or logged unnecessarily.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill exposes a 'view messages' capability that may return user-submitted inquiries, leads, or contact details, but the description does not warn that the data can be sensitive. Without clear notice and handling guidance, an agent or user may retrieve, display, or further process personal data inappropriately, increasing privacy and data-leakage risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal