Back to skill

Security audit

Pipeworx anilist

Security checks for vulnerabilities and agentic risk

Overview

This is a simple anime lookup skill that uses a third-party MCP endpoint and does not request credentials or local system access.

Reasonable to install for ordinary anime searches. Avoid sending private or sensitive text through the skill, and remember that the remote MCP gateway is not locally reviewable from this artifact.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.