Back to skill

Security audit

experience-extraction-course-pro

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed course-development helper with read-only document ingestion that fits its stated purpose.

Install only if you want an agent to help develop training courses from provided materials. Treat any document passed to the helper as content that may be printed into the agent conversation, and avoid pointing it at unrelated private files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill instructs use of a shell command to read local files and the analyzer detected file, shell, and environment-related capabilities, but the skill does not declare permissions or clearly constrain those capabilities in a machine-enforceable way. This creates a transparency and policy-enforcement gap: a caller may invoke a seemingly content-generation skill that can access local data, increasing the risk of unintended file exposure or overbroad tool use.

Tp4

High
Category
MCP Tool Poisoning
Confidence
80% confidence
Finding
The skill is presented as a course-development assistant, but its documented behavior includes local file reading and auxiliary test/document validation behavior not reflected in the high-level description. This mismatch can mislead reviewers or users about the operational surface area, causing them to provide sensitive files or approve the skill without understanding that it can read and emit document contents.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.