Back to skill

Security audit

Company search wdy

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed company-information lookup helper that uses a user-provided WenDaoYun API key for read-only business and legal-risk queries.

Install only if you intend to use WenDaoYun's API and are comfortable storing its API key in an environment variable. Treat the key as sensitive, rotate it if exposed, and note that two route-table entries are marked pending and lack reference files, so those particular lookups may not work yet.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.