maiklubi

Security checks across malware telemetry and agentic risk

Overview

The skill coherently helps an agent use a family sports-club CLI, with disclosed credential persistence that users should secure carefully.

Install only if you are comfortable giving this CLI access to your myclub.fi account and family club data. Treat the local config file as sensitive, remove it with maiklubi config clear when no longer needed, and review any RSVP or calendar actions before allowing an agent to run them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill explicitly states that account credentials are stored in a local config file under the user's home directory, but it provides no guidance about file permissions, encryption, OS keychain use, or the risks of local credential theft. Because this skill handles a parent/family account with access to children’s sports schedules, invoices, and notifications, compromise of that file could expose sensitive family information and allow unauthorized account access.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal