Back to skill

Security audit

KallyAI Executive Assistant

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a real executive-assistant integration, but it gives broad natural-language access to calls, email, bookings, spending-related actions, and account changes without clear approval boundaries.

Install only if you trust KallyAI with real-world delegation. Before using it, review OAuth permissions, set explicit limits for calls, emails, bookings, spending, outreach, subscriptions, and phone routing, and require manual confirmation before third-party contact, purchases, or account changes. Periodically check active goals, inbound rules, connected channels, stored tokens, recordings, transcripts, and contact imports.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description authorizes extremely broad real-world delegation actions such as calls, email, bookings, bills, outreach, and 'any delegation task' without meaningful scope limits or safety boundaries. In an agent-routing context, this can cause over-triggering and unsafe invocation for sensitive or high-impact requests, increasing the chance of unauthorized communications, purchases, account actions, or privacy-invasive tasks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Promoting plain-English triggering as the default interface without clear constraints encourages the agent to interpret free-form user text as authorization to perform consequential external actions. Because this skill can place calls, send messages, and make bookings, ambiguous language may be converted into real-world actions without sufficient confirmation or policy checks.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger 'Handle this for me' is so vague that it can match a wide range of user statements and delegate unspecified tasks to a highly capable assistant. In this skill's context, vagueness is especially risky because the tool can take multi-channel external actions, including calls, emails, bookings, errands, and budget-affecting operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.