Back to skill

Security audit

Agent群组工具免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local multi-agent group messaging helper, with some privacy and activation-scope caveats but no evidence of hidden or malicious behavior.

Install only if you want local agent group messaging with searchable archives. Avoid putting secrets or highly sensitive business data in group messages unless you have reviewed the SQLite path, log path, retention settings, and any callback or external sync configuration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger condition is phrased so broadly ('项目管理、任务规划、进度跟踪、团队协作时使用') that the skill may activate in many ordinary collaboration contexts, including ones where users did not intend to invoke group creation, persistence, or messaging behaviors. In an agent environment with read/exec/write tools, over-broad routing increases the risk of unintended actions, unnecessary data handling, and accidental disclosure into group logs or storage.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises message archiving, logging, local SQLite storage, offline message caching, and an optional callback_url, but does not present a prominent privacy notice or clear warning about retention and possible external transmission. Users may provide sensitive project, agent, or operational data without understanding that it may be stored, logged, cached, or sent to another endpoint.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.