AUSUB

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Tushare-based gold ETF investment helper with scoped local config/history use and no evidence of hidden exfiltration or destructive behavior.

Install only in an environment where you are comfortable exposing `TUSHARE_TOKEN` to this skill and Tushare. Keep user memory files private, avoid storing sensitive income or savings details unless truly needed, and consider reviewing or pinning the `tushare` package before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill declares no permissions, yet its documentation explicitly states it reads environment variables and local files and writes CSV/history data to local paths. This creates a capability/permission mismatch that can mislead reviewers and users about what the skill can access, increasing the risk of unintended exposure of secrets like TUSHARE_TOKEN or modification of local data.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal