Back to skill

Security audit

OPC Skill Prestashop

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed read-only PrestaShop sales assistant that uses a shop URL and API key to query products and stock without evidence of hidden or destructive behavior.

Install only with a PrestaShop Web Service key limited to read-only catalog and stock access for the intended shop. Review the configured shop URL and avoid giving this skill credentials that can modify orders, customers, payments, or other business records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill describes outbound REST/Web Service access to PrestaShop and references sensitive material such as API keys, but it does not declare corresponding permissions. Undeclared network and environment capabilities reduce transparency and can bypass expected review or runtime policy controls, increasing the risk of unauthorized external access or secret handling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:26