Back to skill

Security audit

GoGlobal

Security checks across malware telemetry and agentic risk

Overview

This skill openly helps users deploy a personal proxy, but it handles powerful VPS control keys in a risky way and includes stealth-oriented proxy configuration.

Install only if you intentionally want this exact proxy-deployment workflow and are comfortable giving the assistant a VPS control key. Treat generated API links as secrets, avoid sharing screenshots or browser history, review destructive steps like reinstall carefully, change the panel password, enable HTTPS if possible, and regenerate the KiwiVM API key immediately after setup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The README explicitly frames the skill as helping users deploy VLESS/Reality proxy infrastructure and verify access to services such as Google, ChatGPT, and Claude, indicating the tool is intended for censorship-circumvention rather than a neutral server-management use case. In this context, the misleading presentation reduces informed consent and can facilitate policy evasion or abuse of hosted infrastructure, especially because the workflow minimizes user scrutiny and automates sensitive server control operations.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill goes beyond a deployment helper and steers users into a specific affiliate-linked VPS purchase flow. This creates a conflict of interest and pressures users into acquiring infrastructure that is then immediately used for high-risk network proxy deployment, increasing the chance of abuse and deceptive commercialization.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The skill explicitly instructs the agent to vary Reality fingerprint targets to avoid clustering and detection, which is an evasion tactic rather than normal administration. This meaningfully increases stealth for proxy nodes and makes the workflow more dangerous in context because it is optimizing to resist identification and blocking.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are very broad and generic (for example, telling the AI to install or start the skill) without clear scoping, confirmation boundaries, or user-intent validation. In a high-risk skill that helps provision VPS infrastructure and configure proxy software, this increases the chance of unintended activation and could lead users into exposing sensitive server control information or initiating impactful actions they did not fully mean to start.

Missing User Warnings

High
Confidence
97% confidence
Finding
The prompt requires sending users clickable URLs that embed a live KiwiVM API key in plaintext. Secrets in URLs leak easily via browser history, screenshots, logs, referrals, and shared devices, so this materially increases the chance of credential compromise for a server-control token.

Ssd 3

High
Confidence
99% confidence
Finding
The workflow solicits a highly sensitive server-control credential and operationalizes it by generating browser-executable control links containing the real key. Because that key authorizes privileged actions like command execution, reboot, and reinstall, disclosure can lead to full takeover or destruction of the user's VPS.

Ssd 3

High
Confidence
96% confidence
Finding
The skill repeatedly tells users to paste back full API responses and logs, which may contain secrets, usernames, passwords, network details, or other sensitive server state. This unnecessarily broad data collection increases exposure of privileged information to the model and to anyone with access to the chat transcript.

Ssd 4

Medium
Confidence
94% confidence
Finding
The skill uses a staged, trust-building interaction to first obtain sensitive control data and then guide the user into privileged and destructive actions such as root command execution and OS reinstall. Even if framed as convenience, this pattern lowers user caution and increases the risk of accidental self-compromise or irreversible data loss.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.