Summarize Tianjin

Security checks across malware telemetry and agentic risk

Overview

This is a user-directed summarization skill with a real but disclosed-enough privacy consideration around sending content to third-party AI and extraction services.

Install only if you are comfortable with the summarize CLI and the selected model or extraction providers receiving the content you ask it to summarize. Avoid sensitive, private, regulated, or copyrighted documents unless you have reviewed provider policies and intentionally configured or disabled Firecrawl and Apify fallback behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly encourages summarizing URLs, local files, PDFs, images, audio, and YouTube content using external model providers and optional third-party fallback services, but it does not warn users that submitted content and related metadata may be transmitted off-host. This creates a real privacy and data-handling risk because users may unknowingly send sensitive local documents, transcripts, or browsing targets to OpenAI, Anthropic, Google, xAI, Firecrawl, or Apify.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal