Back to skill

Security audit

Tinyfish

Security checks across malware telemetry and agentic risk

Overview

TinyFish appears to be a legitimate web research and browser automation skill, but it gives agents broad authenticated web-control capabilities without clear consent boundaries for sensitive actions.

Install only if you want Codex to use TinyFish for live web research and browser automation. Treat agent/browser mode as sensitive: require explicit approval before logging in, submitting forms, making purchases, changing account settings, scraping private pages, or running batch/async automations, and avoid exposing secrets or sensitive browsing data unless the task truly requires it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The front-matter description is extremely broad and encourages invocation for generic actions like search, research, extraction, scraping, and browser automation. This can cause the skill to activate in situations where the user did not explicitly consent to remote web access or automation, increasing the chance of unnecessary data exposure or unintended external actions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The instruction to use TinyFish whenever a request depends on live web information, and not to wait for the user to say 'TinyFish' or 'scrape,' creates an ambiguous and overbroad activation boundary. In practice this can make the agent initiate external lookups or site interactions by default, even when the user may expect an offline answer or may not realize a third-party service will be used.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill explicitly supports interacting with websites, clicking through pages, filling forms, and logging in, but it does not warn that these actions can trigger state-changing operations on third-party sites. Without an upfront warning and confirmation requirement, the agent could perform unintended transactions, submit sensitive data, or alter account state under the user's identity.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The authentication guidance tells the operator to log in or set an API key, but it omits privacy, credential-handling, and remote-processing warnings. This is dangerous because users may expose secrets to the environment or send sensitive browsing targets and page content to a third-party service without understanding the trust boundary.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.