YouTube Video To Blog Converter

Security checks across malware telemetry and agentic risk

Overview

This is a coherent payment-integration skill, but it handles money, API keys, user identifiers, and wallet details, so users should only use it with a SkillPay service they trust.

Before installing, confirm you trust the SkillPay endpoint and understand the fee model. Do not put sensitive conversation content or private business details into billing metadata, protect any returned API keys, and make sure users are clearly informed before any per-call charge is made.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The contract explicitly sends `user_id` and arbitrary `metadata` to an external billing endpoint, but it documents no consent, minimization, or user-facing disclosure requirements. In a skill that processes user content, this creates a real privacy and compliance risk because sensitive transcript-derived or business metadata could be transmitted off-platform without the user's awareness.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal