Cloudnet AI Diagnostics

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Cloudnet wireless troubleshooting helper, but it requires a Cloudnet API key and may access sensitive network diagnostic data.

Install only if you trust the mcporter package and Cloudnet endpoint. Use a least-privilege Cloudnet API key where possible, avoid pasting the key into chat or logs, confirm how mcporter stores the bearer token, and treat returned MAC addresses, IPs, usernames, logs, and device telemetry as sensitive operational data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill requires a privileged Cloudnet API key and instructs the user to configure it, but does not warn about its sensitivity, scope, storage, or safe handling. This increases the risk of accidental secret exposure in prompts, logs, shell history, screenshots, or misconfigured environments, which could allow unauthorized access to network management data and actions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The diagnostic workflow retrieves potentially sensitive operational data, including device software versions, platform logs, client identifiers, usernames, IP/MAC data, and user activity-related telemetry, yet the skill does not warn the user that such data will be accessed. Without informed consent and data-minimization guidance, operators may expose personal or infrastructure-sensitive information unnecessarily.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal