Back to skill

Security audit

Story Long Scan

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a purpose-aligned web-novel ranking scraper and report generator, with no evidence of hidden or destructive behavior.

Install only if you are comfortable with the agent making outbound requests to the listed web-novel sites and writing report files. Use a separate browser profile for CDP collection if you do not want existing site logins or cookies involved. Review the output directory before running broad multi-platform scans.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill instructs the agent to fetch live ranking data from multiple external platforms and explicitly references networked scraping scripts, but the metadata does not declare the needed permissions. Undeclared network capability is dangerous because it hides outbound data access from reviewers and policy enforcement, increasing the chance of unintended web access, data exfiltration, or execution in environments that assume the skill is non-networked.

Vague Triggers

Medium
Confidence
72% confidence
Finding
The trigger list includes broad natural-language phrases such as “长篇什么火” and “起点排行”, which may match ordinary user conversation and invoke the skill unintentionally. Accidental activation is risky here because the skill can initiate network scraping workflows and generate external requests without the user clearly intending to run a data-collection tool.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/cdp-utils.js:26