Remotego

Security checks across malware telemetry and agentic risk

Overview

Remotego clearly says it exposes local command-line sessions to a public web link, but that remote terminal access is high-impact and under-warned.

Install or run this only if you intentionally want remote interactive access to a local terminal. Treat the session URL like a password, avoid exposing privileged shells or directories with secrets, prefer a disposable VM/container or restricted working directory, verify the npm package before use, and stop the tunnel immediately when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill explicitly promotes exposing arbitrary local CLI sessions through a public tunnel, but the description and usage guidance do not provide a prominent warning about the risk of internet exposure, command execution, data leakage, or unintended sharing of an interactive terminal. In this context, the omission is dangerous because the skill can publish highly privileged local shells and developer tools, and the stated protections (URL secrecy and short authentication window) are not a sufficient substitute for clear user consent and risk communication.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal