Back to skill

Security audit

Ralph Loop

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about being an autonomous task runner, but it gives broad self-directed authority and sends Telegram progress details without clear opt-in, recipient scope, or task boundaries.

Install only if you intentionally want an aggressive autonomous-execution mode. Before use, confirm where Telegram messages go, avoid sensitive tasks or filenames, and prefer explicit invocation plus approval checkpoints for commands, network access, credential handling, and destructive changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill requires automatic Telegram messages during execution, but this outbound communication is not tightly scoped or clearly disclosed as an essential capability. That creates a data-leak and covert-notification channel, especially because task names, progress, and produced files may contain sensitive user or workspace information.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The execution phase explicitly authorizes broad autonomous behavior such as running commands, creating files, and fetching data, while also instructing the agent to continue without asking the user in most situations. In combination, this removes meaningful guardrails and can lead to unsafe system actions, unintended persistence, or unapproved network/data operations far beyond a narrowly defined task scope.

Vague Triggers

High
Confidence
90% confidence
Finding
The activation condition includes vague triggers such as any task the user expects to be executed autonomously, which is subjective and easy to misinterpret. This can cause the skill to self-activate on ordinary multi-step requests and apply its aggressive autonomy model without clear, informed user consent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill automatically sends Telegram status messages but does not warn the user about this behavior at activation time. Users may unknowingly expose task details, filenames, or progress metadata to an external service, which is particularly risky in sensitive or private workflows.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.