Back to skill

Security audit

Content Researcher

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do its stated job: it searches the web, optionally summarizes results, and writes a report, with no hidden persistence or destructive behavior found.

Install only if you trust the local claw and summarize tools. Avoid confidential keywords or sensitive snippets unless you are comfortable sending them to the configured search and summarization services, and choose the output path carefully because the report file can be overwritten.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill sends user-supplied keywords and potentially collected article content to external search and summarization tools/services, but the description does not clearly warn users about this data disclosure. That omission can lead to accidental sharing of sensitive research topics, proprietary terms, or copyrighted/private content with third parties.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
User-provided keywords are transmitted to an external search tool/service without any explicit consent prompt, privacy notice, or data-classification guardrail. If users enter sensitive research topics, internal project names, or personal data, the skill can unintentionally exfiltrate that information to a third party.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
Collected snippets are forwarded to an external summarization model without warning the user that retrieved content may be sent for AI processing. In a research workflow, snippets may contain copyrighted, proprietary, regulated, or otherwise sensitive text, so silent forwarding increases confidentiality and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.