Back to skill

Security audit

Chart Generator Zc

Security checks across malware telemetry and agentic risk

Overview

This is a local chart-making skill that writes chart files and limited local history, with no evidence of hidden network access, credential access, or destructive behavior.

Install only if you are comfortable running local Bash/Python chart scripts. Choose output paths carefully, use trusted chart labels and titles for HTML/SVG output, and avoid sensitive chart titles or labels when using the history-enabled script.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The script creates a persistent data directory and stores chart artifacts and usage history under the user's home/data path, which goes beyond transient chart rendering and can retain potentially sensitive chart titles, labels, and source-derived data. In this skill context, users may reasonably expect visualization output but not long-term local retention, so the mismatch increases privacy and data-handling risk even though it is not overtly malicious.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.