Back to skill

Security audit

Dcard

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Dcard scraping helper that uses stealth browser automation, with policy and dependency risk but no evidence of hidden theft, persistence, or destructive behavior.

Install only if you are comfortable running stealth browser automation that contacts Dcard and may conflict with Dcard or Cloudflare policies. Keep usage low-volume, avoid private or logged-in content, and review the Camoufox and patchright dependencies before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill explicitly documents network-capable behavior such as fetching Dcard posts and forum listings, but it does not declare corresponding permissions. Undeclared network access weakens review and consent controls because a caller may believe the skill is more limited than it actually is, increasing the chance of unintended external requests.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The declared purpose says the skill fetches a single Dcard article's full content, but the documented commands also support forum-wide listing, latest/hot post enumeration, and all-forum listing. This broader behavior matters because it expands the data collection surface and operational capability beyond what a reviewer or user would reasonably expect from the description.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill metadata describes ordinary content extraction but does not disclose that it relies on a stealth browser to bypass Cloudflare protections. This omission can mislead users about the operational and compliance risk of the skill, reducing informed consent and making it easier to deploy scraping behavior that may violate site protections or policy expectations.

VirusTotal

53/53 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.