Back to skill

Security audit

Check Messages

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims, but it can display private Aicoo messages and contact details from broad prompts without a built-in confirmation step.

Install only if you want your agent to read and display Aicoo inbox data using AICOO_API_KEY. Use explicit Aicoo inbox wording, avoid running it in shared or visible sessions, and prefer a narrowly scoped API key if Aicoo supports one.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill is designed to retrieve and display conversation history, contact information, and pending requests using an authenticated API key, but it provides no explicit user-facing warning, confirmation step, or privacy notice before exposing potentially sensitive inbox data. In a user-invokable messaging skill, this increases the risk of accidental disclosure to someone viewing the screen or of users invoking the skill without realizing it will surface private communications and identities.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest includes broad natural-language triggers such as 'show conversations', 'any new messages', and 'conversation history', which can plausibly match casual user requests and cause unintended invocation of a skill that accesses private authenticated message data. Because this skill reveals inbox contents and contact details, accidental activation is more dangerous than in a low-sensitivity skill and could expose sensitive communications without clear intent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.