Back to skill

Security audit

Feedstream Monitor Free

Security checks across malware telemetry and agentic risk

Overview

This skill sets up a local security-advisory feed monitor that writes local JSON files and fetches public RSS feeds, with no evidence of hidden data theft or destructive behavior.

Before installing, understand that running the examples can create and update local JSON files in ~/workspace/feedstream/monitor and fetch content from configured RSS sources. Review or change STORE_DIR if you want the data stored somewhere else.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The examples create directories and write files under the user's home workspace without an explicit warning or consent step. In an agent setting with exec capability, this can cause unintended filesystem modification, persistent state creation, and silent data placement simply by following the quick-start instructions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.