Back to skill

Security audit

Popeye Prod Tool Free

Security checks across malware telemetry and agentic risk

Overview

This productivity skill is not clearly malicious, but it asks for broad write and shell-execution authority without enough limits or user-control details.

Review this skill before installing. It may be useful for personal productivity workflows, but only use it where you are comfortable granting broad local write and command-execution ability, and require explicit confirmation before it modifies, deletes, exports, installs packages, or runs shell commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill uses very broad natural-language trigger examples such as everyday productivity requests, which can cause the agent to invoke this skill in many ordinary contexts without clear user intent to grant automation, file modification, or command execution. Because the skill also advertises write and exec capabilities, ambiguous triggering increases the chance of unintended privileged actions or unsafe workflow execution.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill declares read, write, and exec capabilities but does not warn users or the agent about filesystem changes, shell execution, network effects, or other side effects. In a generic productivity skill, this is especially risky because common task-management requests could be interpreted as permission to create files, modify local data, or run commands on the host.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.