Back to skill

Security audit

test-publish-dev1

Security checks across malware telemetry and agentic risk

Overview

This skill appears to automate Ozon product distribution, but it uses hardcoded login details and submits a live web action without clear confirmation or scope controls.

Review carefully before installing. Only use this if you trust the publisher, the fixed remote service, and the embedded account. Prefer a test store first, and require a manual confirmation of the category, store, price range, affected products, and target marketplace before allowing any send/publish action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
This appears to be a real security issue because the documented purpose of the skill does not match the described runtime behavior: it reportedly logs into a fixed host with hardcoded credentials, captures screenshots, and automates a generic internal-looking web UI rather than clearly interfacing with Ozon or a documented Crossrui API. In an agent skill, that mismatch is dangerous because it can conceal credential misuse, unauthorized access to an internal service, data leakage via screenshots, and unintended actions on a third-party or internal system.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill’s declared purpose is publishing products to Ozon, but the code instead logs into an unrelated internal web application at a hard-coded IP address and performs UI actions there. This mismatch is dangerous because it can conceal unauthorized automation against an internal system, especially when combined with embedded credentials and a state-changing send action.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The file header and CLI help describe a generic login/dropdown/screenshot automation task rather than the advertised product-publishing workflow. This discrepancy increases the risk of deceptive packaging, making reviewers or users believe the skill is safe for one purpose while it actually automates a different system.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The script clicks a send button automatically after login and field selection, with no confirmation, dry-run mode, or disclosure of what the action does. In an automation skill, this can trigger unintended state changes on the target system, including submissions, transmissions, or bulk operations without meaningful user consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.