Singapore Pools TOTO Results

Security checks across malware telemetry and agentic risk

Overview

This skill fetches public Singapore Pools TOTO results from the official website and does not show hidden data access, persistence, or destructive behavior.

Before installing, note that the skill needs live web access to singaporepools.com.sg to retrieve current results. It would be better if the publisher declared that network permission explicitly, but the reviewed artifacts do not show credential use, local data access, persistence, or destructive actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill instructs the agent to execute a Python script that performs live network retrieval from singaporepools.com.sg, but the skill metadata does not declare any corresponding network permission. Undeclared outbound network access is a real security issue because it expands the skill's capabilities beyond what reviewers and policy controls can reliably understand, and can enable unintended data exfiltration or fetching of untrusted remote content if the implementation changes.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal