Back to skill

Security audit

Manage AI Knowledge Workbench Lite

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local metadata indexer that reads user-selected notes and writes derived dashboard files inside the chosen workspace.

Install only for directories you are willing to let the agent scan for metadata. It should not send note bodies to a model or run in the background, but it will read authorized Markdown, compute file hashes, create local derived outputs, and run a temporary loopback check during build.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill instructs the agent to execute local commands, read source notes, write derived outputs, and probe host tooling, yet the skill declares no explicit permissions. This mismatch weakens security review and user consent because an operator may assume the skill is passive while it actually has meaningful file, environment, and possible network-relevant capabilities through invoked binaries and host CLIs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.