Back to skill

Security audit

Aicoo Snapshots

Security checks across malware telemetry and agentic risk

Overview

This is not malware, but it gives an agent broad note-changing and bulk backup ability through an Aicoo API key without clear confirmation guardrails.

Install only if you trust this publisher and want an agent to manage Aicoo note history with your AICOO_API_KEY. Before use, require explicit confirmation for restores, direct edits, and folder-wide backups, including the target note ID, version ID, and folder scope.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill is scoped as snapshot/versioning, but it also documents direct note editing and folder-wide enumeration/backups. That scope expansion increases the chance the agent performs broader state-changing operations than the user intended, including bulk actions affecting many notes.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Broad triggers like 'restore', 'rollback', and 'undo changes' are ambiguous and may cause the skill to activate for unrelated requests outside note versioning. In an agent setting, overly broad invocation phrases can lead to unintended restores or snapshot operations on user data.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes restore and bulk backup flows without clear warnings that note metadata and potentially note content are transmitted to remote API endpoints, and that restore changes note state. Missing user-facing warnings and confirmation requirements can cause silent data disclosure or unintended rollback of user content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.