Back to skill

Security audit

内审不符合项判定技能

Security checks across malware telemetry and agentic risk

Overview

This skill is a local audit-record tool, but users should treat its stored audit data as plaintext sensitive information.

Install only if you are comfortable storing audit evidence and verification details in a local plaintext JSON file. Clear or replace the bundled assets/nc_data.json if you do not want to use the preloaded audit records, and avoid entering confidential personnel or operational details unless the workspace is access-controlled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill clearly instructs users to run scripts that read and write local files, including automatic creation of assets/nc_data.json, but the skill declares no permissions or equivalent warning about those capabilities. This can mislead users and hosting systems about the skill's actual access level, reducing transparency and increasing the risk of unauthorized or unexpected handling of audit records.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation states that audit non-conformance data will be automatically stored in assets/nc_data.json, and examples include evidence, verifier names, and audit results that may contain sensitive operational or personnel information. Without an explicit persistence warning, retention policy, or confidentiality guidance, users may unknowingly store sensitive audit evidence in plaintext and leave it exposed to other local users, backups, or accidental disclosure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.