Back to skill

Security audit

News Aggregator Skill

Security checks across malware telemetry and agentic risk

Overview

This news skill has expected news-fetching and local report-writing behavior, but users should know it saves reports by default and the referenced helper files are not included in the submitted artifact.

Install only if you are comfortable with the agent contacting the listed public news sources, deep-fetching article text, and saving generated briefings locally in reports/. Because the referenced script and template files are absent from this artifact, verify what implementation will actually be used before relying on the skill for production workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to always save a full report to the reports/ directory without notifying the user or obtaining consent. Implicit file creation can leak sensitive queried topics, create unexpected artifacts on shared systems, and violate least-surprise expectations, especially when article content is deeply fetched and stored.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.