Back to skill

Security audit

Ai Intelligent Live Streaming Assistant

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent live-streaming assistant description, but users should review the external code and configure automation carefully before using it on a real stream.

Before installing, inspect the referenced GitHub repository and requirements file, use scoped or limited platform credentials, test auto-replies, giveaways, and clipping privately, and keep human oversight enabled for public or commercial streams.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill advertises automated moderation, auto-replies, gift acknowledgements, analytics, and auto-clipping, but provides no disclosure about how audience content is processed, what data is collected, or how automated actions may affect user interactions. In a live-streaming context, this can mislead operators and viewers, create privacy and consent issues, and cause harmful or inappropriate automated responses without clear safeguards.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.