Back to skill

Security audit

Logistics

Security checks across malware telemetry and agentic risk

Overview

The skill appears to handle proof-of-delivery data in a way that matches a logistics workflow, but users should treat the personal and location data carefully.

Before installing, confirm where proof-of-delivery photos, signatures, GPS data, recipient names, and driver contact details are sent, who can access them, and how long they are retained. Use it only in workflows where the parties have appropriate notice or consent and avoid collecting more delivery data than necessary.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs capture and upload of recipient name, signature or photo, timestamp, GPS coordinates, and driver contact information, which are sensitive personal and location data. While this is operationally relevant in logistics, the skill provides no privacy guardrails such as consent requirements, data minimization, retention limits, access controls, or jurisdiction-specific compliance checks, creating a real privacy and data-handling risk.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.