签证智能指南

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a visa/travel guidance helper, with one privacy note around live policy lookup but no evidence of malware or destructive behavior.

Install if you are comfortable with a travel guidance skill that may perform live Google searches for destination policy updates. Avoid using live lookup for sensitive or private travel plans unless you accept that the destination query may be visible to Google.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The policy update feature sends user-supplied destination data to Google search without clearly informing the user or obtaining consent. While the destination alone is usually low-sensitivity, travel-related queries can still reveal user interests or plans to a third party, creating unnecessary privacy leakage outside the skill's local dataset.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal