Find MP Skills

Security checks across malware telemetry and agentic risk

Overview

The skill appears to perform expected mini-program and cloud setup steps, with no evidence of hidden or malicious behavior.

Before installing, confirm the target project path, review what community skills or dependencies will be added, use version control or a backup, and run cloud setup against a test environment if billing or existing data could be affected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to install community skills into a local mini-program project and later run setup steps that change project state. Because the documentation does not prominently warn that installation can modify code, dependencies, configuration, and potentially introduce third-party code into the user's project, a user may authorize impactful actions without informed consent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The setup step states that it will select a cloud environment, aggregate cloud functions, generate configuration files, and initialize a database, but presents these as routine follow-up without a clear safety or privacy warning. These are system- and environment-affecting operations that can create resources, alter deployment state, and expose user data or incur cost if performed without explicit acknowledgment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal