Back to skill

Security audit

google trending

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Google Trends RSS fetcher with no evidence of credential access, persistence, local data collection, or destructive behavior.

Before installing, understand that the skill contacts Google Trends over the network and displays public RSS content that may include external news links. It does not need an API key or local file access; the publisher should ideally declare the trends.google.com network dependency explicitly and correct the sensitive-credentials metadata tag.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill performs outbound network access to a public Google Trends RSS endpoint, but the manifest does not explicitly declare that network capability. This is primarily a transparency and policy-enforcement issue: undeclared network use can bypass operator expectations, make review harder, and expand the skill's effective trust boundary to external content.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.