Back to skill

Security audit

Aic Dashboard Free

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a local read-only dashboard, but its setup asks the agent to run a server script that is not included in the package and it displays sensitive local mail/session data through a browser token flow.

Review before installing. Only run the startup command in a workspace where you have verified what scripts/server.js is, and treat the dashboard URL/token as sensitive. Use it on a trusted local machine and clear browser storage if the token or displayed mail/session data should not remain accessible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs users to open a browser URL containing a token and states that the token is automatically stored in localStorage, while the dashboard displays sensitive local email and browser session-status data. Without a clear warning, users may unknowingly expose sensitive information to other local browser users, browser extensions, screenshots, history, logs, or shoulder-surfing, especially because query-string tokens are commonly retained in browser artifacts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.