Back to skill

Security audit

MEGAcmd

Security checks across malware telemetry and agentic risk

Overview

This MEGA cloud-storage skill appears purpose-aligned, but it gives an agent powerful delete, sync, sharing, credential, and public-serving capabilities without enough clear safety gates.

Review this skill carefully before installing. Use it only if you intend to let an agent manage your MEGA account, and require explicit confirmation for deletion, overwrite, sync, public links, mounts, FTP/WebDAV servers, and any command that displays or saves session IDs or recovery keys.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation guidance is broad enough to trigger the skill from generic references such as 'MEGA link' or 'download from MEGA', which can cause an agent to invoke cloud-storage actions in contexts where the user did not explicitly request this skill. In a skill that can upload, delete, sync, share, and expose data over the network, unintended activation increases the risk of privacy-impacting or destructive operations.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The objectives advertise delete, move, sync, sharing, mounting, and server-style exposure capabilities without an upfront high-visibility warning that these actions can permanently alter local/cloud data or expose files publicly. Because this is an agent skill, users may not appreciate that routine language could lead to destructive or externally accessible operations unless the risks are stated clearly before usage.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The reference documents commands that reveal or persist highly sensitive authentication material, including `session` (prints the secret session ID) and `masterkey` (saves the recovery key), but does not pair them with strong disclosure-handling guidance. In an agent skill context, these commands materially increase the chance that an LLM or automation layer may expose secrets in chat output, logs, screenshots, shell history, or insecure files.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The `ftp` and `webdav` sections describe `--public` network exposure and optional TLS, but they do not clearly warn that enabling public access can expose cloud data beyond localhost and may create unintended remote access paths. In an agent-driven environment, a user asking to 'share' or 'serve' files could be led into starting an externally reachable service without understanding firewall, authentication, and transport-security implications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.