Back to skill

Security audit

Mingdao

Security checks across malware telemetry and agentic risk

Overview

The skill appears safe to install, but one API example should be treated carefully because it uses personal identity data.

Before installing or using this skill, do not send real personal identity data to any third-party API unless the provider is vetted, the user has authorized it, and your legal/compliance requirements are satisfied. Prefer test data, masking, or redaction in examples.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The example code sends highly sensitive personal data (`姓名`, `身份证号`) to an external API, but the skill provides no warning about privacy implications, legal/compliance requirements, data minimization, or trust boundaries. In a reusable agent skill, this can normalize unsafe handling of PII and lead users to copy the pattern into production integrations without consent, vendor due diligence, or masking.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.