Back to skill

Security audit

DCC-MCP

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed DCC automation and marketplace-control helper with meaningful local effects, but its risky actions are purpose-aligned and repeatedly gated on user consent.

Install this only if you want an agent to inspect and control live DCC sessions such as Maya, Blender, Houdini, Photoshop, Unreal, or similar tools. Expect it to run local CLI commands, contact local or configured remote gateways, and potentially install or update DCC-MCP components or marketplace skills after approval. Review prompts carefully before consenting to installs, updates, remote gateway registration, UI-control fallback, or actions that modify an open project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill declares only Bash and Read, but the documented behavior clearly includes network access, environment-variable use, and shell-driven installation/update flows. This capability mismatch is dangerous because it can cause a host or reviewer to underestimate what the skill may do, including downloading binaries, contacting gateways, and modifying local state after user approval.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill is presented as a DCC control skill, but it also acts as an installer/bootstrapper and generic gateway client that can download or update the `dcc-mcp-cli` and communicate with REST endpoints. That broader behavior expands trust and attack surface beyond simple DCC task routing, making consent mistakes or supply-chain issues more impactful.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The routing policy instructs agents to invoke this skill first for any DCC-related request, even when the user does not mention DCC-MCP. Such broad automatic interception increases the chance that an agent will enter a more privileged control path than the user expected, including live application control, gateway communication, or setup flows.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The natural-language trigger examples are broad enough to overlap with ordinary conversational requests about supported applications, which can cause accidental invocation of live-control behaviors. In a skill that can enumerate instances, query marketplaces, and control external software, overbroad triggers materially increase the risk of unintended actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.