Back to skill

Security audit

Veteran Proxy

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed proxy-management skill whose sensitive network-routing behavior matches its stated purpose.

Before installing, verify the veteran CLI package and any subscription URL or proxy node provider you use. Proxy operators may be able to observe connection metadata and some traffic depending on encryption, and using proxies may violate workplace, school, or regional policies. Avoid sending sensitive credentials through untrusted nodes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly guides users to configure and run a proxy client, update remote subscriptions, and route traffic through third-party nodes, but it does not warn about the privacy, trust, logging, policy, or network-routing consequences of doing so. In a skill whose purpose is proxy management, that omission is materially relevant because users may expose sensitive traffic to untrusted providers or unintentionally bypass organizational controls without understanding the risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.