Back to skill

Security audit

Airweave

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Airweave search connector that uses a configured API key and collection to retrieve workspace context, with no evidence of hidden, destructive, or persistent behavior.

Install this only if you want an agent to search the configured Airweave collection. Use a least-privilege API key and a collection limited to data the agent is allowed to see, avoid setting AIRWEAVE_BASE_URL unless you trust the endpoint, and treat retrieved workplace content carefully according to your organization's privacy and data-handling rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill requires environment variables and performs network-backed retrieval, but the skill metadata does not declare explicit permissions for those capabilities. That creates a governance gap: agents or reviewers may not realize the skill can access secrets and external services, increasing the chance of unintended data exposure or unsafe execution in sensitive environments.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill is designed to search across connected workplace applications that may contain sensitive business, employee, customer, or regulated data, yet the description gives no privacy warning or consent boundary. Without clear notice, users and downstream agents may invoke broad cross-application retrieval in contexts where minimizing access, confirming scope, or avoiding sensitive content would be necessary.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.