Stock Announcement

Security checks across malware telemetry and agentic risk

Overview

This skill’s goal is understandable, but it asks for Gmail and speaker access while the declared runnable script is missing from the package.

Review before installing. Do not run it until the missing script and config are supplied and inspected. Confirm the Gmail OAuth scope, recipient address, exact report contents, and Sonos speaker target, and avoid audible announcements of sensitive financial details in shared spaces.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill description states that it emails portfolio information through Gmail and announces a summary over a networked Sonos speaker, but it does not warn users about privacy and disclosure risks. This can lead users to unintentionally transmit sensitive financial data to third-party services or expose it audibly to others on the local network or within hearing range.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal