Back to skill

Security audit

Linkding

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a normal Linkding bookmark-management integration, with expected access to the user's configured Linkding API.

Install only if you intend to let the agent use your Linkding API key to read and change bookmarks, including deleting them. Review delete requests carefully and prefer explicit user confirmation for any irreversible bookmark or bundle changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The manifest describes limited bookmark-management actions, but the skill documentation exposes broader destructive and administrative operations such as delete, unarchive, bundle modification/deletion, and profile retrieval. This mismatch can mislead users or orchestrators into invoking a skill with more authority than expected, increasing the risk of unintended destructive actions.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill file documents bookmark deletion, but the manifest description omits that capability. Hidden destructive behavior undermines informed consent and safe tool selection, especially in agentic systems that may choose skills based on descriptions alone.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
Documenting a delete command without warning that it is irreversible creates a meaningful risk of accidental data loss. In an agent setting, examples often become operational defaults, so omission of safety language makes destructive misuse more likely.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.