Content Scraper — AI Trend Monitor

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward trend-monitoring skill that reads user-configured sources, fetches public or API-backed content, and creates daily local reports.

Before installing, review sources.json, use scoped API credentials, confirm that daily 6 AM runs are desired, and choose a notification channel where trend reports and source links are appropriate to appear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs itself to save a report to a local file and notify through a configured channel on a schedule, but it does not mention obtaining user confirmation, providing visibility, or offering controls over these side effects. In an agent setting, silent persistence and outbound notifications can create privacy and consent issues, especially if the report includes scraped content, user niche data, or links derived from configured sources.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal