Back to skill

Security audit

sitemd

Security checks across malware telemetry and agentic risk

Overview

This website-management skill is broadly coherent, but it asks an agent to install/run external tooling and perform lasting site/authentication actions without clear approval or credential-safety boundaries.

Install only if you trust the sitemd publisher and are comfortable letting an agent change and publish your website. Verify the installer and binary source before running them, require manual approval for install, update, delete, deploy, activate, and config changes, and treat magic links and SITEMD_TOKEN like secrets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs sending a login URL over third-party messaging channels without warning that the link is a sensitive authentication artifact. If intercepted, forwarded, or previewed by another party or service, the recipient could complete the login flow and gain unauthorized access.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill recommends creating a long-lived API key and placing it in an environment variable, but provides no warning about credential sensitivity, rotation, scope, or secure storage. In an agent/tooling context, such credentials are high-value secrets that may be exposed through logs, process listings, shell history, CI environments, or misconfigured deployments.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.