Back to skill

Security audit

Tmp.DH2HBD8750

Security checks across malware telemetry and agentic risk

Overview

This Splitwise skill does what it says, but it can read sensitive personal and financial data and change expenses or groups without clear confirmation safeguards.

Install only if you trust the splitwise-mcp package and are comfortable giving it a Splitwise API key. Treat create, edit, delete, and group-membership changes as real account changes, and require explicit confirmation before using those tools. Avoid broad friend, group, notification, or expense listings unless needed for the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises the ability to add, edit, and delete Splitwise expenses, which are financial records, but does not clearly warn that use can modify or remove real user data. In an agent context, this increases the risk of unintended destructive actions or user surprise, especially when natural-language requests are ambiguous.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documented tools expose profile, friend, group, balance, notification, and expense data, including personally identifiable and financial information, without an explicit privacy warning or guidance on minimizing disclosure. In an MCP/agent setting, this can lead to over-collection or over-display of sensitive data beyond what the user intended to access.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.