Robots.txt Generator

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward robots.txt generator and validator with disclosed file and URL handling.

Install only if you need robots.txt generation or validation. When using it, double-check any local file path, remote URL, and output path you provide, because the script can read that file, fetch that URL, and write to that destination.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill advertises and documents capabilities that read local files, write output files, and fetch remote URLs, but no permissions are declared. This creates a transparency and policy-enforcement gap: an agent may invoke filesystem or network actions without explicit user-facing authorization boundaries, increasing the risk of unintended file access, overwrite, or outbound requests.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal