Back to skill

Security audit

Umeng Stats

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a read-only Umeng analytics helper, but it packages and uses sensitive Umeng API credentials for many apps and relies on an unsafe hard-coded credential path.

Install only if you are authorized to access the listed Umeng apps. Treat the bundled Umeng API secret as exposed, rotate or replace it, move credentials into a private user-controlled secret/config location, and fix the hard-coded config path before relying on the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill documentation clearly instructs the agent to invoke a Python script that makes outbound requests to the Umeng Open API, yet no permissions are declared. Hidden or undeclared network capability weakens governance and user/admin awareness, and could allow data exfiltration or unauthorized external access if the skill is installed in a more privileged environment.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal