Back to skill

Security audit

Blog Content Processor

Security checks across malware telemetry and agentic risk

Overview

This skill is a small, purpose-aligned blog/RSS video preview helper with no executable implementation included, though users should be careful with untrusted feeds and media files.

Use this only with feeds and videos you trust, and apply normal media-processing safeguards such as size/time limits and sandboxing where possible. If installing it as an npm package rather than using it as documentation, verify the missing implementation file, dependency versions, and source provenance first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill explicitly describes fetching remote blog/RSS feeds and processing embedded video content, but it does not warn users about the trust and safety implications of retrieving untrusted remote data and media. While this omission is not an exploit by itself, it can lead users to invoke the skill without understanding risks such as contacting attacker-controlled hosts, processing malformed media, or consuming excessive bandwidth/resources.

VirusTotal

46/46 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.