Loopwind

Security checks across malware telemetry and agentic risk

Overview

The skill’s image and video generation purpose is coherent, but its setup asks users or agents to run unpinned remote installer code with local shell privileges.

Use this only if you trust the loopwind publisher and are comfortable with a remote installer modifying your local environment. Prefer reviewing the installer first, pinning to a known release or checksum if available, and rendering third-party templates or image URLs in a sandboxed workspace.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs users to install the CLI by piping a remotely fetched script directly into bash, which executes unreviewed code from the network with the user's privileges. In an AI-agent context this is especially risky because the instruction is presented as a normal setup step, increasing the chance of non-interactive or insufficiently reviewed execution.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal