Epson MCP

Security checks across malware telemetry and agentic risk

Overview

This Epson printer skill is purpose-aligned, but it gives an agent real printer-control and job-cancellation authority without enough safety scoping.

Install only if you trust the MCP server and intend to let an agent control a real printer. Treat raw printing and job cancellation as explicit, user-confirmed actions, preferably limited to trusted users and exact job IDs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill exposes tools that can trigger real-world side effects: printing documents, sending raw printer payloads, and listing or canceling spooler jobs. Without an explicit warning in the skill description, users or agents may invoke these capabilities without understanding that they can cause physical output, waste supplies, reveal queued document metadata, or disrupt active print jobs.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal