google trending

Security checks across malware telemetry and agentic risk

Overview

This skill appears to fetch public Google Trends RSS data and display it, with no evidence of credential use, persistence, or local data access.

Before installing, understand that this skill contacts Google Trends over the network to retrieve public trending-search data. It does not require an API key or access to your local files, though the publisher should ideally declare the trends.google.com network permission explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to fetch data from an external Google Trends RSS endpoint, which is a network capability, but no corresponding permission is declared. Undeclared network access weakens policy enforcement and user/operator awareness, and can allow a skill to make external requests without the expected security review or runtime controls.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal