Back to skill

Security audit

Forklift expert

Security checks across malware telemetry and agentic risk

Overview

This forklift reference skill uses disclosed web lookups for current information, and I found no hidden code, persistence, destructive behavior, or credential handling.

Before installing, understand that forklift questions involving current specs, standards, sales, or market data may be searched on external services such as Google, Bing, Baidu, and standards or industry websites. Avoid including confidential procurement plans, internal incident details, customer names, or regulated data in those queries; for confidential work, ask the agent to rely only on local reference files or confirm before searching. For safety, legal, purchasing, or repair decisions, verify outputs against official sources or a qualified professional.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README says the skill will automatically perform online searches via Google, Bing, or generic web search, but it does not clearly warn users that their query content may be sent to external services. This can expose sensitive operational, commercial, or personal data in prompts, especially because the searches are automatic and can occur without an explicit per-query opt-in.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to perform live web searches based on user questions but does not require notice, consent, or minimization before transmitting query content to third-party search engines. If users include sensitive operational details, model inputs, internal product names, or regulated information, those details may be disclosed externally without the user's awareness.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The standards-verification workflow directs the agent to query external standards websites using user-supplied standard numbers or requests, again without warning that the request may be sent to third parties. In enterprise or regulated settings, even apparently harmless standards questions can reveal procurement plans, compliance gaps, or internal investigation topics.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.