Unofficial Urban Dictionary API

Security checks across malware telemetry and agentic risk

Overview

This skill is a small disclosed helper for querying an unofficial Urban Dictionary API, with no hidden file access, persistence, credential use, or destructive behavior found.

Install only if you are comfortable sending slang lookup terms to an unofficial third-party API. Results may include offensive or NSFW user-generated content, but the skill itself appears narrowly scoped to fetching and displaying API results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The skill explicitly instructs the agent to make outbound HTTP requests to an external API, but the skill metadata does not declare corresponding network permissions. This mismatch weakens transparency and policy enforcement, making it harder for a platform or reviewer to reason about the skill's external data flows and increasing the risk of unintended data exposure if user input is sent to the remote service.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal