Cloud Upload Tencent

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Tencent COS upload helper, with the main caution that cloud uploads should be explicitly requested and confirmed.

Install only if you intend to use Tencent COS. Use a least-privileged COS key, confirm the exact local file or folder and cloud destination before each upload, and do not let generic requests like "share this" or "back this up" run without explicit Tencent COS confirmation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger conditions are broad and map to common user intents like uploading files, generating links, backing up files, or sharing documents. In an agent environment, this can cause the skill to activate in many ordinary conversations and then prompt for or operate on sensitive local files and cloud credentials, increasing the chance of unintended data transfer or exposure.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal