Back to skill

Security audit

Data Analyst Cn Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward data-analysis helper with one underdocumented optional callback parameter but no evidence of hidden, destructive, or unrelated behavior.

Install only if you are comfortable letting the agent read and process the datasets you provide and run local Python-style analysis commands. Avoid using callback_url with sensitive results unless you trust the destination and understand what your agent will send there.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill accepts a callback_url for asynchronous completion but does not disclose that results or metadata may be sent to an external destination. In a data-analysis context, outputs may contain sensitive business or personal data, so silent outbound transmission creates a real risk of unintended data exfiltration or SSRF-like misuse if the platform dereferences arbitrary URLs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.