Back to skill

Security audit

HF Daily Researcher Min

Security checks across malware telemetry and agentic risk

Overview

This skill is a research-reporting helper with disclosed web search, local report storage, sub-agents, and optional Feishu publishing, but users should treat research interests and reports as potentially sensitive.

Install only if you are comfortable with the skill using your research focus, searching the web, saving report artifacts locally, and potentially creating Feishu documents. For private or unpublished research, run it local-only, avoid cron until configured, and confirm before any Feishu upload.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill’s documented outputs are local reports, but the execution flow additionally states reports may be uploaded to Feishu. That creates an undeclared external data egress path for synthesized research content and potentially user-derived context, which is risky because users may not realize generated reports leave the local environment. The risk is elevated because this skill also reads user research focus and persistent profile context, so exported reports may contain sensitive or identifying information.

Ssd 3

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to extract research-direction data from persistent files such as USER.md and MEMORY.md and feed that into configuration and reporting flows. This is dangerous because it expands data collection from persistent memory without clear scoping, minimization, or consent, and that profile data may later influence generated reports or be sent to external destinations. In this skill’s context, the danger is higher because the workflow includes saving and potentially publishing reports, increasing the chance of unintended disclosure of personal or organizational research interests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.