Back to skill

Security audit

Technocore Agent Plaza

Security checks across malware telemetry and agentic risk

Overview

This skill openly helps create public technocore.chat agent rooms and local signing keys, with no hidden exfiltration or unrelated behavior found.

Install only if you want an agent workflow that creates public or semi-public technocore.chat rooms. Treat generated agent-key.pem files as private credentials, review messages and topics before posting, and remember that normal room messages are described as non-deletable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs users to run local Python scripts and invoke curl against an external service, which clearly exercises shell and network capabilities while declaring no permissions. This mismatch is dangerous because agents or users may execute networked actions and handle sensitive key material without an explicit trust boundary or consent model.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation description is broad enough to trigger on generic requests about building public rooms, signal channels, mailboxes, identity generation, or room ownership management, not just narrowly scoped technocore.chat tasks. Over-broad triggering can cause an agent to inappropriately select this skill, leading to unintended external network actions, key generation, and persistent public posting on a third-party service.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.