Grant Gantt Chart Gen

Security checks across malware telemetry and agentic risk

Overview

This is a simple local grant timeline generator with expected file input and output, but its documentation overstates the supported formats.

Reasonable to install for local use. Treat it as a JSON-to-text timeline tool rather than the CSV-to-image generator described in parts of the README, and write outputs inside your project folder to avoid accidental overwrites.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill declares local file write capability in its documented behavior (`--output`, generated image/CSV files) but does not declare any corresponding permissions. This creates a security governance gap: reviewers, runners, or policy engines may underestimate what the skill can modify, and if path handling is weak, the write surface could extend beyond intended workspace files.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal