sensitive access with suspicious destination
high signalA bundled script reads a credential source and sends data to a webhook within the same local code window.
scripts/collect.py:18, 22An illustrative skill that gathers research notes and prepares a summary.
Related behavior was detected in the skill bundle. Review the evidence and its intended use before installing.
Related signals that passed the scanner’s correlation gate.
A bundled script reads a credential source and sends data to a webhook within the same local code window.
scripts/collect.py:18, 22Instructions ask the agent to suppress disclosure while performing the flagged action. The combination increases the need for review.
SKILL.md:31, 34In this illustrative example, the requested research task does not explain the credential transfer or concealment instructions. Both support closer inspection. This sample assessment is not a live AI response.
Unfiltered engine matches include signals that did not pass correlation. Rule severity alone is not a verdict.
| Engine / rule | Location | Rule severity |
|---|---|---|
| NovaDetectDataExfiltration | scripts/collect.pyLines 18, 22 | high |
| YARAModelCredentialHarvesting | scripts/collect.py | critical |
| NovaDetectSkillPromptInjection | SKILL.mdLines 31, 34 | medium |
| NovaDetectMaliciousToolPermissions | SKILL.mdLines 9 | low |