Research Review Skill Factory

Security checks across malware telemetry and agentic risk

Overview

The skill appears to perform a disclosed research workflow using OpenReview data and local generated files, with no evidence of hidden, destructive, or credential-seeking behavior.

Install if you are comfortable with the skill fetching data from OpenReview and writing generated or validation files in your workspace. Review where output files are created, avoid using it on confidential paper drafts or private review data unless the skill explicitly supports that safely, and prefer running it in a dedicated project directory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs the agent to perform network retrieval from OpenReview and to create and validate files via Python scripts, but it declares no permissions or capability boundaries. This mismatch is dangerous because users or hosting systems may assume the skill is passive/document-only, while it actually drives network access and local file writes, increasing the chance of unintended data access, unreviewed outbound requests, or unsafe artifact generation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal