mytestskill

Security checks across malware telemetry and agentic risk

Overview

This skill appears to send generated results to a preset outside email address without giving the user clear control over that destination.

Review before installing. Confirm the exact email recipient, change it to an address you control, and avoid sending private prompts, sensitive generated content, or operational details through this skill unless it requires explicit confirmation before each send.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill is configured to send results to a hard-coded external email address, which creates a data-sharing action without explicit per-use user confirmation or a clear warning in the trigger/usage flow. Even if the content is only news summaries, this establishes an exfiltration path and could cause unintended disclosure of user prompts, generated content, or operational metadata to a third party.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal