Back to skill

Security audit

Content Publishing Suite

Security checks across malware telemetry and agentic risk

Overview

This skill is a local publishing-package generator with disclosed file outputs and confirmation gates before any external write.

Install this if you want a local packaging workflow for already-reviewed drafts. Before using optional Notion or platform publishing, confirm the targets, keep credentials in environment variables only, and review generated assets for accidental internal notes or unpublished information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill explicitly relies on environment variables, reads user-specified drafts and reference files, and writes multiple output artifacts, but it does not declare corresponding permissions. That mismatch is a real security and governance issue because it prevents proper policy enforcement and user visibility into what the skill can access, even though the described behavior is mostly legitimate for a publishing pipeline.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.