Back to skill

Security audit

AlphaLens API

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AlphaLens research integration that uses an API key and external lookups, with no artifact-backed evidence of hidden persistence, credential theft, or destructive behavior.

Install only if you intend to use AlphaLens and are comfortable sending company names, domains, product descriptions, organization IDs, and any explicitly submitted pipeline documents to AlphaLens. Be aware that public company domains may also be sent to Google's favicon service for logo fetching; avoid using it for confidential/internal hostnames or sensitive deal materials unless your AlphaLens account and policies allow that.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The workflow explicitly says to use this for a quick competitive landscape or market map when the user has not requested bottom-up analysis, which broadens execution beyond the AlphaLens-specific trigger boundaries defined in the skill metadata. This can cause the skill to activate on generic research requests and send organization IDs and domains to AlphaLens and Google favicon endpoints without the user having clearly asked for AlphaLens-specific processing.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The workflow explicitly instructs the agent to supplement AlphaLens data with its own unstated knowledge, then incorporate those results into the output. This breaks source-boundary guarantees, can introduce hallucinated or unverifiable companies into a supposedly AlphaLens-grounded analysis, and expands behavior beyond the declared skill scope in a way that can mislead downstream users or trigger unintended lookups.

Context-Inappropriate Capability

Low
Confidence
85% confidence
Finding
The skill discloses that it fetches favicons from Google's public service, which is a third-party network interaction outside the core AlphaLens API scope. Even though the fetched resource is low sensitivity, this broadens data egress, leaks researched domains to an external party, and creates an undeclared dependency that may violate least-privilege or user expectations in sensitive research contexts.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill/page describes automatic triggers for ingestion in very broad terms (for example, forwarding email, drag-and-drop upload, and API submission) without clearly constraining when processing occurs or what guardrails apply. In a product centered on ingesting documents and syncing enriched data into CRMs, ambiguous trigger behavior can lead to unintended collection and processing of sensitive deal materials, making this a real security and privacy weakness even if not overtly malicious.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The description promotes automatic document ingestion, OCR, analysis, and extraction from uploaded files and links, but omits any explicit warning about privacy, retention, or handling of confidential materials. Given the context—pitch decks, DocSend links, emails, and investor/deal data—users may submit highly sensitive information, so the lack of clear privacy disclosure and safety boundaries materially increases the risk of unauthorized processing, oversharing, or compliance failures.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The browser extension is advertised as working 'wherever you browse' and surfacing intelligence without leaving the page, but it does not explicitly warn that extension functionality may access page content, metadata, or sensitive browsing context. In an enterprise research workflow, users may browse confidential internal systems, investor portals, or customer environments, so insufficient disclosure around extension access creates meaningful risk of unintended data exposure.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The instruction to use this workflow for 'a quick competitive landscape or market map' is broad and underspecified, and only excludes bottom-up analysis. In context, that ambiguity is risky because the workflow performs external enrichment and disclosure-sensitive lookups, so an overbroad trigger can lead to unintended third-party data sharing or tool use outside the user's intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.