Back to skill

Security audit

Azure Cosmos DB Python

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a normal Azure Cosmos DB helper, but users should treat its examples as live cloud database changes.

Install only if you intend to let the agent help manage Azure Cosmos DB containers. Use least-privilege Cosmos credentials, prefer test databases first, and review any create, replace, upsert, or delete command before running it because it can change persistent cloud resources and billing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The markdown includes live examples for create, replace, upsert, delete, and create-if-not-exists operations without any warning that they modify persistent cloud data and may incur cost. In an agent skill context, users or downstream agents may copy or execute these snippets against production resources, causing unintended data loss, schema/container changes, or billable throughput changes.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.