Back to skill

Security audit

Rumi

Security checks across malware telemetry and agentic risk

Overview

Rumi is a coherent human-matching chat skill, but users should be careful about sharing personal context and API tokens.

Install only if you are comfortable using Rumi as an external service to meet and chat with real people. Before starting a match, ask to review the exact description that will be sent and remove private details. Treat the Rumi API token like a password and rotate it if you think it was exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The proactive activation criteria are broad and behavior-based, which can cause the agent to suggest an external human-matching service during ordinary conversations without a clear user request. In this skill, that increases the chance of unnecessary disclosure of sensitive conversational context to a third-party service and nudges users toward external interaction they may not have intended.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to gather context and send a rich description to a human-matching service, but it does not require a clear privacy warning or explicit informed consent before transmitting potentially sensitive conversation details. Because the service connects the user to real humans, the privacy risk is elevated: information may be exposed both to the platform and to a matched stranger.

Ssd 3

High
Confidence
98% confidence
Finding
The setup flow tells the user to paste their API token back into chat for storage, which exposes a long-lived secret inside the conversational channel and any associated logs, transcripts, or downstream tooling. In an agent environment, chat is often not an appropriate secret-handling boundary, so this creates a significant credential leakage risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.