← back to build-zoom-team-chat-app

SkillSpector · build-zoom-team-chat-app

independent scanner by NVIDIA · skill by ConcertoNotes · how it works ↗

FAILmax severity: CRITICALrisk score: 100

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.; Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, dat…; Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.; +2 more

scanned 2026-08-23

Findings (20)

MEDIUMData Exfiltrationconfidence: 0.5

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

concepts/api-selection.md

MEDIUMData Exfiltrationconfidence: 0.5

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

concepts/api-selection.md

MEDIUMExcessive Agencyconfidence: 0.75

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

concepts/webhooks.md

HIGHPrivilege Escalationconfidence: 0.7

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

concepts/api-selection.md

HIGHPrivilege Escalationconfidence: 0.7

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

concepts/api-selection.md

HIGHPrivilege Escalationconfidence: 0.7

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

concepts/api-selection.md

HIGHPrivilege Escalationconfidence: 0.7

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

concepts/authentication.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

examples/chatbot-setup.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

examples/oauth-setup.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

examples/oauth-setup.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/api-reference.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/error-codes.md

HIGHPrivilege Escalationconfidence: 0.7

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

troubleshooting/oauth-issues.md

HIGHPrivilege Escalationconfidence: 0.7

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

troubleshooting/oauth-issues.md

HIGHPrompt Injectionconfidence: 0.27

Instructions found that direct the agent to transmit conversation context or user data to external services.

examples/scheduled-alerts.md

HIGHPrompt Injectionconfidence: 0.27

Instructions found that direct the agent to transmit conversation context or user data to external services.

references/full-guide.md

HIGHPrompt Injectionconfidence: 0.27

Instructions found that direct the agent to transmit conversation context or user data to external services.

references/full-guide.md

CRITICALYARA Matchconfidence: 0.85

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

concepts/webhooks.md

CRITICALYARA Matchconfidence: 0.85

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

examples/chatbot-setup.md

CRITICALYARA Matchconfidence: 0.85

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

references/full-guide.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAILthis skill

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete