Back to skill

Security audit

Ambil jadwal sholat (imsak, subuh, dzuhur, ashar, maghrib, isya) untuk kota/kabupaten di Indonesia dari API Muslim api.myquran.com (sumber Kemenag Bimas Islam). Gunakan saat user minta jadwal sholat hari ini / tanggal tertentu / 1 bulan untuk lokasi tertentu, atau butuh mencari ID kab/kota.

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it claims: fetch Indonesian prayer schedules from a clearly disclosed public API.

Before installing, understand that using this skill will contact api.myquran.com with the location and date or month you request. It does not appear to access private files, credentials, or persistent storage, but a stricter manifest should explicitly declare the network domain it uses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill clearly relies on outbound network access to query api.myquran.com, but the metadata shown in SKILL.md does not declare any permissions. This is a real security governance issue because it hides the skill's actual capability from reviewers and runtime policy systems, even though the destination and purpose appear benign.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.