News Aggregator Skill 0.1.0

Security checks across malware telemetry and agentic risk

Overview

This skill behaves like a disclosed news aggregator, with ordinary web-fetching and local report-saving risks but no evidence of hidden or malicious behavior.

Install only from a source you trust, preferably in a virtual environment. Be aware that using the skill contacts public news sites and linked article pages, and generated reports may persist locally under reports/ with topics that reveal your interests. Ask for strict keywords or strict time windows if you do not want the skill to broaden searches or add supplementary older items.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill mandates always saving full reports to the local reports/ directory and presenting them in chat, without any user consent, opt-out, or notice about persistence. Automatically writing fetched and possibly sensitive query-derived content to disk can create unintended data retention, leak browsing interests, and expose stored artifacts to other users, tools, or processes on the host.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The 'all sources' global scan prompt is overly broad and does not define limits on source count, result size, time range, or request cost. In an agent setting, this can trigger excessive external fetching, long-running operations, or unintended data collection, increasing denial-of-service and cost-exhaustion risk.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal