Ora社媒主页搜索专家

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed social-media lookup skill that sends user searches and an auth token to fixed external API endpoints, with no evidence of hidden or destructive behavior.

Install only if you are comfortable sending search terms, company names, domains, platform selections, and the TPAgent.key authorization token to api.topeasychina.com. Avoid submitting confidential prospecting lists or sensitive business research unless that third-party service is acceptable for your data handling needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README documents that user-supplied keywords, company names, or domains are sent via POST to external third-party endpoints and authenticated with a token, but it does not disclose this data transfer or provide any user-facing privacy/security warning. In a lead-generation/social media search context, queries may contain sensitive business intelligence, customer targets, or identifiers, so silent transmission to a remote service creates a meaningful privacy and trust risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal