Back to skill

Security audit

AdMapix

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AdMapix API client for fetching ad and app intelligence data, with no evidence of hidden execution, exfiltration, or destructive behavior.

Install this if you want your agent to query AdMapix for ad and app intelligence data. Be aware that your search terms, app/company identifiers, and API-authenticated requests go to AdMapix, and download/revenue values are third-party estimates rather than official figures. Keep the API key in the host secret/config store and do not paste it into chat.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The manifest description contains very broad trigger phrases across multiple languages and use cases, which can cause the skill to activate in situations beyond a narrowly scoped ad-data retrieval request. Overbroad activation increases the chance that unrelated user data or queries are routed to this external-data skill unnecessarily, expanding exposure to third-party transmission and making misuse easier.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.