test转储

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed data-transfer automation skill, but users should treat it as capable of importing data into another system if they implement or run the referenced script.

Install only if you intend to move data between these systems. Verify the target URLs, review the generated Excel file before import, test outside production first, use least-privilege accounts, and enable cron only after confirming repeated imports are safe.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly automates exporting data from one system and importing it into another, but it does not warn users that it will modify data in the target system or recommend validation before import. In an RPA/data-transfer context, this omission increases the risk of accidental bulk changes, propagation of bad data, or unintended uploads to the wrong environment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal