Project Ghost

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only web-reading API skill whose external URL processing and API key requirement are disclosed and fit its stated purpose.

Use this for public web pages only. Before installing, confirm you are comfortable storing a Project Ghost API key and sending requested URLs, page contents, and related metadata to the hosted Project Ghost service; avoid sensitive or internal links unless you trust that provider's data handling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The usage examples are phrased as ordinary conversational requests such as 'Read this page and tell me what it's about' and 'What are the top stories on Hacker News right now?'. In agent systems that auto-route based on natural-language matching, these broad triggers can cause unintended activation during normal conversation, leading to unplanned browsing and external API calls.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to send URLs to a third-party endpoint but does not clearly warn that submitted URLs, fetched page contents, and associated metadata will be transmitted to an external service. This can mislead users or downstream agents into sending sensitive targets or internal research subjects off-platform without informed consent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal