Back to skill

Security audit

Millimetric Query

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-only helper for querying Millimetric analytics, with some privacy-sensitive raw event examples that users should handle carefully.

Install only if you intend to let the agent read Millimetric analytics. Use a least-privilege read-only key, avoid exposing the key in shared logs, prefer aggregate queries when possible, and query raw user or anonymous IDs only for authorized debugging or support work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents endpoints and recipes for retrieving raw events and user-specific activity, including filtering by user_id and returning event timelines. Even with a read-only API key, this can expose potentially sensitive analytics or behavioral data and normalizes access to per-user telemetry without any privacy warning, minimization guidance, or access-control caveat.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.