TOSR Publish Then Update Test

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed live-API publishing tool, with expected state-changing actions but no evidence of hidden or malicious behavior.

Install only if you intend to let the agent manage real remote resources through the API. Before any publish, update, or delete, verify the target account, project, and resource ID, and prefer dry-run or confirmation steps where available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly states it performs real publish, update, and delete operations against a live API, but it does not include a clear warning about side effects, required authorization boundaries, or the fact that persistent external state will be modified. In an agent setting, this increases the chance of unintended destructive actions or use in the wrong environment, especially because deletion is part of the normal workflow.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal