Scavio Reddit

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Reddit research integration that uses a disclosed Scavio API key and disclosed Scavio endpoints, with no hidden code or persistence found.

Install only if you are comfortable sending Reddit search terms and Reddit post URLs to Scavio using your Scavio API key. Avoid putting secrets, private customer details, or sensitive business strategy into search queries unless your organization has approved that provider.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to send Reddit queries and post URLs to a third-party API but does not disclose the privacy implications of transmitting potentially sensitive research terms, monitored topics, or user-provided URLs off-platform. This is not inherently malicious, but it is a real privacy/transparency weakness because operators may unknowingly exfiltrate business-sensitive or personal-interest data to Scavio.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal