Back to skill

Security audit

Ctxly Chat Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed anonymous chat helper, but its very broad activation wording could cause sensitive agent data to be sent to an unauthenticated external chat room unintentionally.

Install only if you want an agent to use ctxly.app as a lightweight anonymous chat channel. Do not use it for secrets, personal data, regulated data, credentials, audit-critical records, or trusted agent coordination unless you add explicit user confirmation and strict scoping around when messages may be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The skill documentation is internally inconsistent about data export and persistence: earlier sections describe output/export/save/convert operations, while the free-version limitations say message persistence and history export are unsupported. This can mislead an agent or operator into assuming retention or export guarantees that do not exist, creating privacy, integrity, and operational risk when chat data is relied on for auditability or recovery.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation description is overly broad and ambiguous, making it unclear when the skill should be selected and what safeguards apply. In agent ecosystems, vague activation criteria can cause unintended invocation in unrelated contexts, increasing the chance of sending sensitive content to an anonymous third-party chat service without deliberate user intent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The capability coverage section enumerates a very wide set of loosely connected keywords as trigger scope, which can cause promiscuous matching by an agent runtime. That broad scope is especially risky here because the service is anonymous and unauthenticated, so accidental activation may disclose prompts, results, or coordination data to an external room-based system.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill promotes anonymous, unauthenticated chat but does not provide a clear warning about confidentiality, impersonation, tampering, room hijacking, or message integrity risks. In this context, omission of those warnings is dangerous because users and agents may treat the channel as trustworthy coordination infrastructure even though the document itself states there is no identity verification or trusted communication.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.