Back to skill

Security audit

Syft News Pool (CLI)

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Syft News CLI helper whose account-based news access and local briefing files fit its stated purpose.

Install this if you are comfortable with the Syft CLI using your Syft account and followed topics to generate personalized news. Review any generated profiles, briefings, storylines, or guidance files because they may reveal interests or editorial preferences.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The default prompt is phrased as a broad, natural-language request to 'build a profile-aware daily briefing,' which can cause the skill to be invoked in routine user interactions without a narrowly defined trigger. Combined with allow_implicit_invocation: true, this increases the chance of over-broad activation, unintended data use, or the skill influencing responses in contexts where the user did not explicitly request Syft News access.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.