Back to skill

Security audit

Telegram身体扫描工具

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly coherent for Telegram body scanning, but it handles sensitive body-video data without enough privacy detail and includes some unrelated capability claims.

Review before installing. Use only for consenting adults and only with videos the subject has agreed to submit. Confirm where AnthroVision bridge data is processed, retained, accessed, and deleted, and constrain the skill's read/exec/write permissions if your agent platform allows it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill documentation advertises unrelated capabilities such as CVE correlation, baseline compliance auditing, and bulk asset risk scoring that do not match a Telegram body-scan workflow. This intent/documentation divergence can mislead an agent into over-broad or unintended security-analysis behavior, increasing the chance of misuse, privilege creep, or unsafe tool invocation beyond the stated body-measurement purpose.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill processes body videos and derived measurements, which are sensitive biometric and privacy-impacting data, yet the documentation does not prominently disclose retention, sharing, processing location, or consent/privacy risks in a clear warning section. In this context, the data is especially sensitive because it involves identifiable body imagery transmitted to a bridge service, so weak privacy disclosure and controls materially raise compliance, misuse, and user-harm risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.