Korta Model Usage

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow local reporting helper that summarizes CodexBar usage costs without hidden sharing, persistence, or destructive behavior.

Install this only if you are comfortable with CodexBar and its Homebrew tap. The skill itself appears limited, but the underlying usage logs and generated summaries may reveal private model usage and cost information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill instructs the agent to execute local shell commands (`codexbar`, `python`) and read local files/stdin, but it declares no permissions to reflect those capabilities. This mismatch can bypass least-privilege expectations and cause the skill to access local cost logs or arbitrary input files without transparent permission gating, increasing the chance of unintended data exposure or unsafe command execution in an agent environment.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal