Back to skill

Security audit

Tmp.QQxghgrKJd

Security checks across malware telemetry and agentic risk

Overview

This Zillow skill is clearly described as read-only access to Zillow listing data and signed-in saved Zillow items, with the main caveat that it relies on a browser extension and the user's Zillow session.

Install only if you are comfortable letting an MCP server use your signed-in Zillow browser session through a Chrome extension. Prefer project-level MCP configuration when possible, and treat saved searches/homes as private account data even though the advertised tools are read-only.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger description is overly broad because it activates on essentially any request involving Zillow properties, prices, or saved Zillow activity, which can cause the skill to be invoked in contexts the user did not explicitly intend. In a skill that can access signed-in browser-backed Zillow data, overbroad routing increases the chance of unnecessary exposure of private saved searches or homes and can cause inappropriate tool use on ambiguous prompts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.