Back to skill

Security audit

Cheat Code Paid

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent enterprise knowledge search helper, but it automatically caches and can team-share sensitive internal query results without enough scoping or review controls.

Install only in environments where users understand that internal queries and results may be sent to configured services, cached locally, and shared with teammates. Use narrowly scoped tokens, disable or limit caching and prefetch for sensitive work, and require review before adding retrieved internal or licensed content to shared storage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill promotes querying external and internal data sources but does not clearly warn that user prompts, internal terms, or retrieved content may be transmitted to third-party or internal services. This creates a meaningful risk of unintended data disclosure, especially in enterprise use where prompts often contain confidential project, architecture, or security information.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The local cache and team-sharing features normalize storing query contents and results without warning that these artifacts may contain sensitive user input, proprietary documents, or internal search terms. In practice this can silently persist sensitive material on disk or expose it to collaborators beyond the original requester.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill encourages retaining prior query contents in local cache and redistributing them through shared knowledge storage without any semantic checks for sensitivity, ownership, or authorization. In an enterprise context, prior queries can embed incident details, credentials-adjacent material, unreleased designs, or regulated data, so automated retention and sharing materially increases confidentiality risk.

Ssd 3

Medium
Confidence
97% confidence
Finding
The instruction to save retrieved results into a team knowledge base can cause broad disclosure of previously retrieved internal or licensed content without verifying that the requester is authorized to redistribute it. Because the skill is explicitly enterprise-oriented and promotes collaboration, this context makes accidental over-sharing more likely and more damaging.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.