Back to skill

Security audit

现场不良数据分析助手

Security checks across malware telemetry and agentic risk

Overview

This skill performs the manufacturing quality data analysis it advertises, with local parsing and report generation, but users should be aware that generated reports may load an external Google font.

Install only if you are comfortable having uploaded manufacturing quality files parsed into derived JSON/report content. For confidential or air-gapped environments, remove or block the Google Fonts link in generated HTML before opening reports, and choose output locations that match your data-handling policy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding
The skill instructs the agent to read user-supplied files and write derived outputs such as JSON and HTML reports, but it does not declare corresponding permissions or boundaries. This creates a transparency and governance gap: users and the platform may not realize the skill can access uploaded file contents and persist transformed artifacts, increasing the risk of over-broad file handling or unintended data exposure.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The generated local HTML pulls Google Fonts from an external domain, creating an unnecessary network dependency when the report is opened. This can leak metadata such as user IP, access time, and report-open events to a third party, and may violate manufacturing or internal-network isolation requirements in sensitive environments.

Missing User Warnings

Low
Confidence
72% confidence
Finding
The skill asks users to upload quality files and then transforms them into parsed JSON and generated HTML reports, but the user-facing description in that section does not clearly warn about this processing and artifact generation. In a manufacturing context, uploaded files may contain sensitive operational or quality data, so insufficient disclosure can lead to inadvertent exposure or mishandling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.