Back to skill

Security audit

AIsa Search Command Center

Security checks across malware telemetry and agentic risk

Overview

This is a coherent AIsa web-research skill that sends user-provided searches or URLs to AIsa using a declared API key.

Install only if you trust AIsa with the searches, prompts, system instructions, and URLs you submit. Avoid using it with secrets, private internal URLs, personal data, or confidential business material unless sending that content to AIsa is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding
The skill declares no explicit permissions even though it requires environment-variable access and performs network-backed research. This weakens transparency and consent boundaries for users and hosting agents, increasing the chance that sensitive credentials are exposed to tooling and that outbound network activity occurs without clear declaration.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The documented purpose frames the skill as general research/search, but the implementation reportedly includes deeper capabilities such as site crawling, URL extraction, academic filtering, direct calls to multiple external model/search endpoints, and custom system prompts. That mismatch is security-relevant because reviewers and users may authorize a broader and more invasive capability set than they intended, enabling unexpected data collection, external transmission, or prompt-injection exposure through crawled content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.