Board Webmcp

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed board-automation helper that can visibly edit a shared demo board, so it should be used deliberately but does not show malicious behavior.

Install this only if you intend to let an agent operate the shared board demo or a local board. Keep the dedicated browser profile isolated, avoid placing secrets on the shared board, and ask the agent to read/export the board and confirm before making visible edits in collaborative sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation without defining any trigger scope, user-consent boundary, or contextual constraints. Because this skill can connect to a shared board service and perform inspection or edits via local-mcp, automatic invocation increases the chance of unintended access or modification when user intent is ambiguous.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The examples include state-changing commands such as nodes.upsert, edges.upsert, layout.apply, and diagram.export against a shared board target, but they do not warn that these operations can modify a live collaborative workspace. In this skill's context, users are explicitly encouraged to work against board.holon.run or a visible headed session, so copy-pasting these examples can unintentionally alter shared state, disrupt collaborators, or overwrite board structure.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal