Back to skill

Security audit

dailyhot

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed hot-trends lookup helper that uses a configured DailyHot MCP service and does not include executable code or hidden persistence.

Before installing, configure the DailyHot MCP server and base URL only if you want the agent to query external hot-list data. Review any separate Cron or subscription setup carefully, since this skill describes that mode but does not itself install a scheduler.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description advertises very broad triggers such as 热点追踪/热搜查询/内容选题/趋势分析 without defining clear activation boundaries, which can cause the agent to invoke this skill in loosely related contexts. Over-broad routing increases the chance of unintended external data access, unnecessary network calls, and use in contexts where trend-scraped content may be inappropriate or misleading.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.