Pipeworx microlink

Security checks across malware telemetry and agentic risk

Overview

This is a small disclosed connector for Microlink screenshots and metadata, with the main caution that submitted URLs go to an external service.

Install only if you trust Pipeworx/Microlink and the mcp-remote package. Do not use it with internal sites, private pages, signed URLs, tokens in query strings, or other sensitive identifiers unless you are comfortable sending that information to the remote service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises a remote Microlink MCP endpoint and emphasizes that it is free and requires no API key, but it does not warn users that submitted target URLs and related request metadata will be transmitted to a third-party service. This can lead users to unknowingly send sensitive internal URLs, tokens embedded in URLs, or other confidential browsing targets to an external provider, creating a privacy and data exposure risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal