Strategic Alignment

Security checks across malware telemetry and agentic risk

Overview

This skill is a local strategic-planning helper that analyzes user-provided OKR JSON and does not show hidden data sharing or privileged behavior.

Safe to install for local strategy and OKR review. Treat OKR and strategy files as confidential business data, and only run the checker on JSON files you intentionally want analyzed locally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The manifest declares a Python tool (`alignment_checker.py`) and the content references reading OKR data plus automated analysis, which implies operational capabilities without an explicit permissions declaration. Undeclared file-read and possible network access create a trust gap: users and the host may invoke code that can access local data or external services without clear consent or policy review.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal