Back to skill

Security audit

pubmed-edirect

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed PubMed/NCBI command-line integration that requires manual external installation and may write local research output files.

Install this only if you are comfortable manually reviewing and running NCBI's installer, modifying your shell PATH, and allowing EDirect commands to contact NCBI. Run examples from a dedicated workspace and change default output filenames when you need to avoid overwriting or retaining sensitive research results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill clearly instructs users to download and execute an external installer script and then use network-capable CLI tools, but it does not declare corresponding permissions/capabilities in a structured way. This creates a trust and review gap: automated policy enforcement may underestimate the skill's ability to reach external services and pull code from the internet.

Missing User Warnings

Low
Confidence
72% confidence
Finding
Several examples write logs, XML, abstracts, CSVs, and SQLite databases to fixed local filenames without warning, which can unintentionally overwrite existing files or leave persistent data behind. In an agent or automated environment, this can cause data clobbering, workspace contamination, or unanticipated retention of query history and results.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.