Back to skill

Security audit

Multica Manager

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Multica task manager, but it gives broad automatic authority to create or control agent tasks and forward content to other sessions without clear confirmation or scoping.

Install only if you intend to let this skill manage Multica agents on your behalf. Before using it, require explicit confirmation before task creation, stop/restart commands, or sessions_send fallback; avoid putting secrets or sensitive business details in task titles or messages; and periodically review or clear the local Multica task log.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill auto-activates on broad, natural-language phrases like '开始讨论', '检查一下', and '查看进度', which can easily appear in ordinary conversation without the user intending to trigger task dispatch or agent-control behavior. Because the skill can create issues, message external agents, and write logs, accidental activation can cause unintended external actions and data exposure.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to create issues for other agents and append task details to a persistent local log, but it does not warn users that their prompts may be forwarded to external agents or stored on disk. This creates a consent and privacy risk, especially if users include sensitive business, personal, or credential-like information in task descriptions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.