Summarize-AI 内容摘要助手

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward summarization skill that installs and invokes an external CLI, with expected use of model-provider and extraction-service API keys.

Before installing, verify the Homebrew tap and avoid using production or overly broad API keys. Do not summarize confidential files, private URLs, or sensitive media unless you are comfortable with that content being processed by the configured model provider and any enabled extraction services such as Firecrawl or Apify.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly encourages summarizing URLs, local files, and YouTube links using third-party model providers and optional extraction services, but it does not warn users that submitted content may be transmitted off-host to those external services. This creates a real data exposure risk because users may pass sensitive documents, private URLs, or copyrighted/internal content under the assumption the processing is local or self-contained.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal