Back to skill

Security audit

Robin

Security checks across malware telemetry and agentic risk

Overview

Robin is a disclosed local note-library skill that stores and reviews user-provided content in a chosen folder.

Use a dedicated Robin state directory, keep topics_dir and media_dir inside it, and remember that saved entries may include personal notes and copied local images. Enable scheduled recall only if you want your host agent to resurface entries automatically, and use move/delete commands intentionally because they modify the local library.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding
The skill documentation directs the host agent to read and write local files, run Python scripts, pass environment variables, and optionally handle http(s) video URLs, but the skill declares no permissions or capability boundaries. This creates a trust gap where a host may enable broader file, shell, env, and possible network access than the user realizes, increasing the chance of over-privileged execution or misuse if the surrounding tooling does not enforce least privilege.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal