Back to skill

Security audit

Huo15 Yh Usage

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrowly scoped usage-billing helper that discloses sending a user-provided Fireworks-style API key to a specific billing endpoint, with no persistence or hidden local access found.

Only use this with an API key you are authorized to inspect. Treat the fsk key as a secret: avoid pasting it into shared chats or shell history when possible, do not store it, and confirm the request is going to the documented Huo15 usage endpoint for this billing report.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The aliases include very broad generic terms such as “token 账单”, “model usage”, “用量统计”, and “费用统计”, which can cause the skill to trigger for user requests that are not specifically about this Fireworks usage-billing function. Over-broad invocation increases the chance that a user is prompted to supply or paste a sensitive API key in the wrong context, creating avoidable credential-handling risk and accidental execution.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the operator to take a customer-provided `fsk-...` API key and send it in an Authorization header to a remote endpoint, but it does not prominently warn about the sensitivity of the credential, consent requirements, retention, or logging exposure. Because API keys are bearer secrets, mishandling during collection, transmission, display, or shell history/logging can enable unauthorized access or later abuse beyond the immediate billing query.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.