xdoc-translation

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Xdoc translation helper that sends user-selected text or documents to Xdoc and does not include hidden code, installers, or automatic execution.

Install only if you are comfortable sending selected documents or text to Xdoc for translation. Use a revocable API key, avoid confidential or regulated material unless Xdoc's terms meet your requirements, and review before creating, editing, or deleting glossary and translation-memory resources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The manifest advertises document and text translation features but does not clearly warn users, near the feature description, that submitted content is sent to an external Xdoc service and retained for 7 days. Because this skill handles potentially sensitive documents and text, the omission can mislead users into sharing confidential data without informed consent, increasing privacy and compliance risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal