Back to skill

Security audit

Ovitalmap Parcel CSV

Security checks across malware telemetry and agentic risk

Overview

This skill coherently generates and maintains local Ovitalmap parcel CSV archives, with file writes and archive updates disclosed and gated by user confirmation.

Install only for workflows where you want an agent to create and maintain local Ovitalmap parcel CSVs. Set OVITALMAP_WORKSPACE to the intended project folder, review coordinate/provider/code confirmations before allowing writes, and keep backups of important parcel archives.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs use of environment variables and local scripts that read and write files, but no permissions are declared. This creates an authorization gap where an agent may access the workspace or modify/archive CSVs without an explicit permission boundary, increasing the risk of unintended file exposure or tampering.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.