Mcp Builder

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is aligned with its stated purpose of generating MCP server scaffolds and does not request credentials, persistence, or hidden access.

Use this in a new or clearly chosen project directory, review the generated package files and MCP config before running them, and provide credentials only later if your specific generated server requires them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs generating a full project scaffold with multiple files, but it does not require user confirmation, safe output boundaries, or warnings about creating or overwriting files. In an agent setting, this can lead to unintended filesystem modifications, clobber existing code, or cause large-scale writes based on ambiguous prompts, especially because the skill is designed to autonomously bootstrap projects.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal