Back to skill

Security audit

cargo-diagnostics

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Cargo diagnostics skill that reads workflow and billing data to explain failures and costs, with disclosed paid rerun and admin-token cautions.

Before installing, make sure you trust the Cargo CLI package and are comfortable giving it access to your Cargo workspace data. Use the lowest token scope that works, confirm the active workspace with whoami, and require explicit approval before any workflow edit, connector reauthentication, rerun, batch creation, or admin billing query.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest describes a post-hoc diagnostic skill focused on tracing runs, graph execution, root-cause analysis, and credit attribution. Lines L63-L65 instruct the operator to change the graph, stage via draft release, pilot records, and fan out, which is optimization/change-management guidance rather than explanation of what a run or batch did.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest centers on explaining failures, wrong outputs, missing rows/columns, execution paths, and credit attribution. Lines L50-L61 present a lever table telling users how to reduce spend by reordering nodes, swapping providers/models, changing failure behavior, and cutting phone lookup from default chains, which is operational optimization beyond pure diagnostics.

Missing User Warnings

Low
Confidence
78% confidence
Finding
This markdown file instructs users to perform operational actions that can change system state by re-running records and creating a new batch. Although the document later mentions that re-runs of paid nodes are paid actions, the warning is separated from the first action-oriented instructions and there is no up-front caution about operational impact before users reach those steps.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.