Back to skill

Security audit

Tmp.6CgulS5VeG

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Vibo MCP integration, with disclosed account access and event-management actions, but users should protect any stored Vibo credentials or captured session tokens.

Install only if you intend to let the MCP server access and modify your Vibo event data. Prefer the normal email/password path when appropriate, keep `.mcp.json` and `~/.vibo-mcp/session.json` private, and revoke or rotate Vibo sessions if those files or captured tokens may have been exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs users to capture authentication tokens from a signed-in browser session and persist them to a local session file, but it does not provide any warning about the sensitivity of those tokens, storage protections, or the risks of reuse if the file is exposed. Because these tokens can grant account access without a password, compromise of the captured values or the saved session file could enable unauthorized access to the user's Vibo account and related event data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.