Ping Tool

Security checks across malware telemetry and agentic risk

Overview

This skill is a small, disclosed ping helper for network diagnostics, with no evidence of hidden access or persistence.

Install only if you need basic network connectivity checks. Use it only against hosts you own, manage, or have permission to test, and note that the bundled script always sends four pings and does not support the documented options.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to invoke a shell-capable network utility (`ping-tool`/`ping`) but declares no permissions. This creates a mismatch between the documented behavior and the declared security model, which can lead to undeclared command execution and network probing against user-supplied hosts.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal