Back to skill

Security audit

Agent3 Hub

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate remote MCP hub integration, but it needs review because it gives broad third-party invocation access with limited privacy, credential, and downstream trust guidance.

Install only if you want your agent to use Agent3 as a broad remote gateway to external agents, APIs, and search services. Treat the API key as an account credential, avoid sending secrets or regulated data through the hub, verify individual resources before invoking them, and require explicit approval for generic invoke or register actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill routes user prompts and tool inputs to a remote third-party MCP endpoint, but it does not clearly warn users that their queries and invocation data leave the local client and are processed by hub.agent3.me. This creates a real transparency and privacy risk because users may unknowingly send sensitive prompts, internal data, or identifiers to an external service.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill requires an API key in an environment variable and shows placing it directly in client configuration, but provides no warning about credential handling, storage, or exposure risks. Users may embed live tokens in config files, logs, screenshots, shared repos, or desktop settings without understanding the security implications.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.