Web Publisher Skill

Security checks across malware telemetry and agentic risk

Overview

The skill mostly does what it says, but it needs review because an error path can expose a reusable publishing API key in the chat or logs.

Review before installing. Use it only for documents and URLs you are comfortable sending to tools.siping.me and any rewrite providers. Avoid confidential or regulated files unless you have approved that data flow. If login-status ever reports persist-failed and shows WEB_PUBLISHER_API_KEY, treat that key as exposed and rotate or revoke it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README explicitly states that arbitrary URLs and local documents are processed server-side, but it does not clearly warn users that sensitive local files and fetched content will be transmitted to a remote service. This creates a real privacy and data-handling risk because users may unknowingly upload confidential documents to infrastructure outside their local environment.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises optional AI rewriting and says processing occurs in the cloud, but it does not clearly disclose that user-provided content may be sent to remote AI services for rewriting. That omission is security-relevant because sensitive text may be exposed to third-party processors without informed consent or clear data-boundary expectations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal