Back to skill

Security audit

Opencollab Autolist

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it asks an agent to act on a live freelance marketplace with too little control around accounts, credentials, and public proposals.

Review carefully before installing. Only use it with explicit per-action confirmation, official OpenCollab API documentation, user-provided limited-scope credentials, and clear limits on account creation, profile edits, listings, proposal volume, scheduling, and credential storage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill is framed as a broad autonomous growth agent that can register accounts, create profiles, post skills, bid on jobs, and monitor listings without clearly defined activation constraints, user confirmations, or scope limits. That makes it easy for an agent to over-apply the behavior to real external services, causing unintended account actions and marketplace activity.

Missing User Warnings

High
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to populate a marketplace profile and later automate matched-job bidding and daily monitoring, but provides no warning about irreversible external effects such as account creation, public profile changes, spam-like proposals, or financial/reputational consequences. In context, this is more dangerous because it targets a live freelancing marketplace and encourages autonomous outward-facing actions on behalf of the user.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The API section tells the agent to use web search to discover current endpoints and authentication methods, which can lead to unsafe credential handling, scraping of unofficial auth flows, and collection or misuse of secrets without defined safeguards. This is especially risky because the skill is designed to perform authenticated actions against a third-party platform, potentially exposing user credentials or enabling unauthorized automation.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.