Security audit
Minimax Usage
Security checks across malware telemetry and agentic risk
Overview
The skill appears to check Minimax usage as advertised, but it reads and executes a broader .env file than the setup instructions disclose.
Review the script before installing or running it. It is meant to call Minimax, but you should either change it to read a .env file in the skill directory or export only MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID in your shell; avoid running it against a shared parent .env that may contain unrelated credentials or shell commands.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
