Back to skill

Security audit

Freelance Autobot

Security checks across malware telemetry and agentic risk

Overview

This skill needs review because it is designed to automatically send freelance proposals and create a public CryptoGig profile without clear approval steps.

Install only if you are comfortable with a skill that may act on freelance accounts. Use dry-run behavior first, review every proposed profile and proposal manually, and do not allow live submissions or profile changes unless you have confirmed the exact content and target platform.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly advertises auto-submitting proposals to external freelance platforms without any stated confirmation, approval gate, or warning to the user. This can cause unauthorized external actions, spam submissions, reputational damage, and unintended contractual or financial commitments, especially because the workflow says it personalizes and submits proposals autonomously.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents creating a CryptoGig profile but does not warn that it may publish or modify user-facing account data on an external service. Silent profile creation or editing can expose inaccurate information, publish sensitive details, or alter a user's professional identity without informed approval.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.