Back to skill

Security audit

Swiss Phone Directory

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Swiss phone directory lookup skill with some credential-handling and privacy documentation cautions, but no hidden or malicious behavior found.

Install only if you are comfortable sending lookup queries and your search.ch API key to search.ch. Use a dedicated API key, avoid sharing screenshots or logs that reveal it, and prefer a secret manager or temporary environment variable over putting the key in shared dotfiles or gateway configs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
This skill enables lookup, retrieval, and display of personal and business contact information from a third-party directory, including reverse phone lookup, but does not provide any user-facing privacy or appropriate-use warning. That omission can lead to misuse of personal data, unexpected disclosure in chat outputs, and compliance/privacy issues because users are not warned that queries and results may involve personal information processed by an external service.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The troubleshooting guidance tells users to run `echo $SEARCHCH_API_KEY`, which prints the secret directly to the terminal and may expose it via screen sharing, terminal logging, shell history capture tools, or recorded CI/session logs. While this is common troubleshooting advice, it unnecessarily reveals a credential and should be treated as insecure documentation practice.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.