Back to skill

Security audit

Dada

Security checks across malware telemetry and agentic risk

Overview

This appears to be a documentation-only integration skill whose personal-data examples are expected for delivery callback handling, with no evidence of hidden execution or data theft.

Install only if you intend to work with this delivery/API integration. When testing or troubleshooting, use mock payloads or redact real customer, courier, address, phone, callback URL, and credential values; keep webhook logs access-controlled and minimal.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly describes callback handling and includes personal data fields such as receiver name, phone number, address, and courier mobile number, but it does not warn users to avoid exposing real production PII in prompts, logs, or example payloads. In an AI-assisted integration context, developers may paste live webhook bodies, API requests, or debugging logs into the assistant, creating a realistic risk of unintended sensitive data disclosure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.