Time Tool

Security checks across malware telemetry and agentic risk

Overview

This is a small, disclosed command-timing helper; it can run user-specified local commands, but that capability matches its stated purpose and no hidden persistence, exfiltration, or destructive behavior was found.

Install only if you intend to let the agent run local commands for timing. Use it in workspaces where command execution is acceptable, and avoid timing commands that could mutate important files, expose secrets, or access sensitive accounts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill exposes shell-command execution semantics (`time-tool <command> [args...]`) but does not declare any permissions, which creates a mismatch between documented capabilities and the security model. This is dangerous because users or orchestration layers may treat the skill as low-privilege while it can invoke arbitrary commands, enabling command execution, data access, or chaining with other tools depending on runtime constraints.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal