Back to skill

Security audit

competitive-product-research

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent competitive research helper with a local intake form and report templates; its browser and test-script references are disclosed and scoped to form handling or developer regression testing.

Before installing, be aware that the skill may open a bundled local HTML intake form and may place your entered research parameters into the host agent flow or clipboard. Treat any private PRDs, screenshots, or internal metrics you provide as sensitive input, and only run the included Chrome regression test if you are intentionally modifying the form asset.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill instructions reference capabilities beyond plain text generation, including reading local assets, opening/copying HTML files, and invoking Python-based test scripts. When a skill uses file, network, or shell-like behaviors without explicit permission declarations, operators and users cannot accurately assess or constrain what the skill may access, increasing the risk of unintended file exposure or command execution in capable hosts.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The stated purpose is competitive research report generation, but the file also instructs browser launching, DevTools/WebSocket interaction, DOM inspection, and local form regression testing. This mismatch is dangerous because a user invoking a research skill would not reasonably expect local browser automation or debugging interfaces to be used, which can expand attack surface and enable unintended local system interaction in permissive environments.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.