HN Reader

Security checks across malware telemetry and agentic risk

Overview

This Hacker News reader does what it says: it fetches public Hacker News content and does not request credentials, local files, persistence, or privileged access.

Install only if you want a Node-based tool that makes public API requests to Hacker News. Prefer installing from the included lockfile, and consider narrowing the trigger phrases in your agent setup so generic requests like "latest" or "jobs" do not accidentally activate it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes generic phrases like 'new', 'latest', and 'front page' that are common in ordinary conversation and can cause unintended skill activation. In an agent environment, overly broad triggers can route user requests to the wrong skill, leading to confused behavior, unwanted network access to external APIs, and reduced trust in the system.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal