← back to build-zoom-team-chat-app
SkillSpector · build-zoom-team-chat-app
independent scanner by NVIDIA · skill by ConcertoNotes · how it works ↗
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.; Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, dat…; Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.; +2 more
scanned 2026-08-23
Findings (20)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
concepts/api-selection.md
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
concepts/api-selection.md
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
concepts/webhooks.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
concepts/api-selection.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
concepts/api-selection.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
concepts/api-selection.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
concepts/authentication.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
examples/chatbot-setup.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
examples/oauth-setup.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
examples/oauth-setup.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
references/api-reference.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
references/error-codes.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
troubleshooting/oauth-issues.md
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
troubleshooting/oauth-issues.md
Instructions found that direct the agent to transmit conversation context or user data to external services.
examples/scheduled-alerts.md
Instructions found that direct the agent to transmit conversation context or user data to external services.
references/full-guide.md
Instructions found that direct the agent to transmit conversation context or user data to external services.
references/full-guide.md
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
concepts/webhooks.md
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
examples/chatbot-setup.md
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
references/full-guide.md
What the verdicts mean
SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.
Overall severity LOW (risk score in the safe range)
Overall severity MEDIUM
Overall severity HIGH
Overall severity CRITICAL
Scan could not complete