Cubox Integration (International & China)

Security checks across malware telemetry and agentic risk

Overview

This skill does what it advertises: it saves user-provided URLs or memos to Cubox using a user-configured API URL.

Install only if you want the agent to save selected content to Cubox. Treat CUBOX_API_URL like a password, avoid logging or sharing it, and do not send confidential, regulated, or secret content unless you are comfortable storing it in Cubox.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill explicitly requires access to an environment variable containing a secret API URL and uses network-capable scripts, but it does not declare any permissions to reflect those capabilities. This creates a transparency and consent problem: users or hosting platforms may not realize the skill can read sensitive credentials and send data off-box, increasing the risk of unintended secret exposure or data exfiltration if the scripts are modified or misused.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal