Tickflow Realtime

Security checks across malware telemetry and agentic risk

Overview

This appears to be a normal TickFlow API integration that needs a service API key and outbound requests, with a permissions-documentation gap to review.

Install only if you intend to let the agent call TickFlow on your behalf. Use a least-privilege TICKFLOW_API_KEY, confirm requests go only to the TickFlow API, and avoid giving the skill unrelated sensitive data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill explicitly instructs the agent to read an API key from the environment and make outbound HTTP requests, but it does not declare corresponding permissions. This creates a capability/permission mismatch that can bypass user or platform expectations about secret access and network use, increasing the risk of unintended data exfiltration or unauthorized external calls if the skill is invoked in a broader agent context.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal