1password Cli.Bak

Security checks across malware telemetry and agentic risk

Overview

This is a coherent 1Password CLI guide, but it gives agents direct power to read, change, cache, and delete secrets with limited guardrails.

Install only if you intentionally want an agent to manage a narrowly scoped 1Password vault. Use a dedicated service account with the minimum permissions needed, avoid personal or production vaults, require explicit approval before create/edit/delete actions, do not cache secret values, and rotate or revoke the token when the task is complete.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents a permanent delete operation for secrets/items without any warning, confirmation step, or recovery guidance. In the context of an agent-facing secret-management skill, this increases the chance that an LLM or automation flow could delete credential records unintentionally, causing loss of access or operational disruption.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal