Snooker Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent snooker lookup tool, with a minor credential-storage caveat if users choose its optional setup command.

Prefer setting SNOOKER_API_KEY instead of running setup. If you use setup, treat ~/.nanobot/workspace/snooker/config.json as a secret file and restrict local access to it. Also note that direct script execution may require uv even though the metadata lists python3.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The `setup` command stores the API key in plaintext at `~/.nanobot/workspace/snooker/config.json` without warning the user or restricting file permissions. On multi-user systems or shared environments, other local processes or users may be able to read the credential, leading to unauthorized use of the API key.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal