python 查询技能

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local Python database query helper that retrieves passenger-flow data from a user-configured SQL Server.

Install only if you intend the agent to query that SQL Server. Configure credentials through protected environment variables, use a dedicated read-only or stored-procedure-limited database account, and avoid sharing prompts or logs that may contain returned business data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
76% confidence
Finding
The skill establishes a live connection to an external SQL Server and retrieves data without any user-facing disclosure or consent mechanism. In an agent/skill context, undisclosed outbound network/database access can surprise operators, expand the trust boundary, and expose sensitive business data if the skill is invoked in environments where users do not expect external data access.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal