Back to skill

Security audit

老兵知识采集器

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, user-triggered workflow for searching public WeChat article results and bulk-importing selected URLs into an IMA knowledge base.

Before installing, confirm you want a skill that can search Sogou WeChat, create local batch/output files, and add many URL entries to an IMA knowledge-base folder. Pay close attention to the target knowledge base and folder because the skill says IMA has no delete API, so cleanup may require manual action in the IMA interface.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill describes and instructs the agent to perform file reads/writes and network access, but it does not declare corresponding permissions or capabilities in its metadata. This creates a transparency and governance gap: operators may approve or run the skill without understanding that it can scrape external sites, persist local data, and modify batch files used for import workflows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.