Back to skill

Security audit

新闻聚合引擎

Security checks across malware telemetry and agentic risk

Overview

This news aggregation skill has no executable payload, but it asks for broad read/exec capability and includes an under-explained callback URL that could send results outside the agent.

Review before installing. Use it only with agent permissions you are comfortable granting, avoid providing sensitive queries or credentials unless the destination and provider are clear, and do not use callback_url unless you trust the endpoint and understand that generated content may be transmitted there.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
Documenting a callback_url parameter without warning that results may be transmitted to an external endpoint creates a real data egress and SSRF-style risk. In an agent context with read and possibly exec capabilities, users may supply sensitive queries or derived content that could be sent off-platform without clear consent or hostname restrictions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.