Back to skill

Security audit

Minecraft Custom Mod Builder

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed remote Minecraft mod-building helper, with the main cautions being external uploads and possible misuse of generated gameplay/client mods.

Install only if you are comfortable sending mod specs, textures, generated artifacts, and any uploaded source archives to AgentPMT/File Manager for remote processing. Do not upload private or proprietary code/assets unless intended, keep account and wallet secrets out of prompts/logs, and use generated client utilities or prank/chaos mechanics only in single-player, private, or explicitly authorized servers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The schema explicitly documents outbound API routes to a third-party service and multiple actions that can transmit project contents, uploaded source archives, images, and generated artifacts, but it does not include a clear user-facing warning or consent requirement about external data transfer. In an agent setting, this can cause users or downstream agents to send proprietary code, assets, or sensitive project materials off-platform without informed awareness.

Ssd 4

Medium
Confidence
92% confidence
Finding
The skill explicitly normalizes creation of deceptive or potentially abusive game modifications such as prank items, fake-glitch effects, chaos traps, stalker behaviors, and 'hacked client' presets. While framed as in-game content, these patterns can facilitate griefing, deceptive UX, unfair multiplayer advantage, or evasion of user intent boundaries, so the skill lowers safety barriers for harmful mod creation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.