Back to skill

Security audit

Mobb Vulnerabilities Fixer

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly coherent for Mobb vulnerability remediation, but one monitoring workflow can trigger background scans and automatic code changes without a fresh confirmation step.

Install only if you intentionally use Mobb for repository security remediation. Use a trusted, user-managed Mobb MCP server, keep API keys scoped and revocable, confirm the repository path before scans, and disable or avoid auto-fix unless you are prepared to review and recover local code changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The manifest describes a skill used when the user asks to scan, fix, remediate, or apply Mobb fixes, which implies user-directed operations. The documentation for `check_for_new_available_fixes` states that background scans are triggered and that fixes may be applied automatically if auto-fix is enabled, introducing autonomous modification behavior not clearly reflected in the manifest description.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This markdown file states that if auto-fix is enabled, fixes may be applied automatically, which can modify user code and affect repository state. The description does not include any explicit caution, confirmation expectation, or warning about reviewing changes before use.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The file says that setting `rescan: true` forces a new scan and upload, implying repository content or metadata may be transmitted externally. The markdown does not provide a privacy or data-handling warning to users about what is uploaded or when transmission occurs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.