Scheduling Engine

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed paid scheduling API that handles appointment and staff data, with no local code execution or hidden behavior found.

Before installing, confirm you trust gateway.mcfagentic.com and are comfortable sending appointment details, attendee emails, staff information, and notes to that service. Get appropriate consent before transmitting customer or staff data, avoid sensitive notes unless necessary, and understand the x402 per-call payment model.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill sends and processes personal scheduling data such as names, email addresses, staff identifiers, notes, and appointment details through external API endpoints, but it does not warn users or downstream agents that this data leaves the local environment. This can lead to unintentional disclosure of personal or business-sensitive information, especially when autonomous agents pass customer data to third-party services without explicit consent or data-handling awareness.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal