Back to skill

Security audit

Ai Intelligent Api Management

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only API management skill; its main caution is that it points users to run external code that is not included in the reviewed package.

Before installing, review the referenced GitHub repository, requirements.txt, and app.py because they are not included in this package. Run it first in a test environment and avoid production API credentials or sensitive API data until you trust the external implementation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill is described in very broad terms as an API management system covering design, documentation, testing, versioning, and monitoring, but it does not define clear activation boundaries, permitted actions, or operational constraints. In an agent setting, this can cause overbroad invocation and unintended execution paths, increasing the chance that the agent performs sensitive development or network-related actions without sufficient user confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.