Back to plugin

Security audit

ZeroGPU Router

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed ZeroGPU cloud-routing plugin, but users should understand that prompts, including PII redaction inputs, are sent to ZeroGPU and login stores an API key locally.

Install only if you are comfortable using ZeroGPU as a third-party processor for the text you route through these skills. Do not use the redaction, extraction, chat, summarization, or classification skills on secrets, credentials, regulated data, or confidential code unless your organization has approved ZeroGPU for that data. Run signin only when you intend to persist a ZeroGPU API key on this machine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description uses broad trigger terms like redact, scrub, mask, anonymize, or sanitize a passage before sharing or logging, without clear constraints on when it should or should not activate. In this skill's context, over-broad activation is risky because the implementation sends raw user text to a third-party hosted API before redaction, so the skill may be invoked in situations where the user did not intend external disclosure of sensitive data.

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.