NBA Today Pulse

Security checks across malware telemetry and agentic risk

Overview

This looks like an NBA data skill, but its actual network and cache behavior is broader than the package describes.

Install only if you are comfortable with a sports-data skill making outbound web requests from your agent environment. Prefer running it where network egress is restricted to ESPN/NBA hosts, and avoid passing non-NBA URLs to the official-report feature.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill declares no permissions, yet its own instructions explicitly require shell execution, outbound network access, environment-variable reads, and access to bundled local files. This mismatch weakens sandboxing and review guarantees because the runtime may permit more capability than the manifest communicates, making operator trust and policy enforcement less reliable.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal