Back to skill

Security audit

Industry Deep-Dive Pipeline

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed editorial workflow that creates local article review files and runs local checks, with no hidden publishing, persistence, or data exfiltration behavior found.

Install this if you want a structured research-and-review pipeline for long-form industry articles. Use a dedicated case directory and provide only source materials and writing-profile files you intend the agent to read; the skill is designed to stop before any publishing workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs the agent to read multiple local reference files and write a full set of output artifacts, but the metadata declares no permissions. This mismatch is risky because it obscures the skill's actual file-system capabilities from reviewers and policy enforcement, increasing the chance of unintended file access or overwrites if the runtime infers capabilities from content rather than explicit declarations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.