Back to skill

Security audit

Tmp.ChIoCYDxiX

Security checks across malware telemetry and agentic risk

Overview

This Infinite Campus helper is purpose-aligned but needs Review because it can access very sensitive student records and possibly send school messages with broad triggers and limited consent guidance.

Install only if you intend to let an agent access your Infinite Campus parent account. Configure it for your own authorized account only, avoid storing credentials where others can read them, disable the browser-cookie fallback if you do not want session reuse, and require explicit confirmation before retrieving sensitive categories like behavior, fees, documents, or before sending any message.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The manifest and top-level description emphasize grades, attendance, assignments, messages, and documents, but the documented tools also expose behavior incidents, fees, and cafeteria balance data. This creates a transparency gap: users or calling agents may invoke the skill without understanding the full scope of sensitive student information accessible through it, increasing the risk of over-collection or inappropriate disclosure.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger text is broad enough to match generic school-related requests such as grades, attendance, assignments, messages, or documents without clearly requiring that the user actually wants Infinite Campus. In an agentic environment, this can cause the wrong skill to activate and send highly sensitive educational data requests to an external MCP server when the user may have meant another system or only wanted general advice.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises access to highly sensitive student records and also includes an account-impacting action: sending messages. Without an explicit warning, consent step, or action boundary, users may not realize the privacy implications of retrieving behavioral, attendance, academic, and document data, or that the agent can perform outbound communication on their behalf.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.