Back to skill

Security audit

Find Stl

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it claims: search Printables and download 3D model files to a local folder.

Install only if you are comfortable with the skill contacting Printables and saving downloaded 3D model files, including ZIP archives, into a local output directory. Use a dedicated downloads folder and inspect or scan downloaded models before opening them in slicer or printer software.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill clearly describes and demonstrates network access plus local file writes, but no explicit permissions are declared in the skill metadata. That creates a transparency and governance gap: an agent or reviewer may invoke a capability that downloads remote content and writes files locally without clear up-front authorization boundaries.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The notes mention that fetch downloads model files and writes a manifest, but the skill description lacks an explicit warning about performing network downloads and local output writes. This can lead to unintended execution in automation contexts where users expect a search-only operation or are not prepared for untrusted external files to be saved locally.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.