zotero-write

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it edits a local Zotero database, with disclosed backup guidance and no evidence of hidden network, credential, or persistence behavior.

Install only if you want a local tool that directly edits your Zotero SQLite database. Confirm the database path, close Zotero first, keep the backup requirement, and test on a copy before using it on an important library.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill clearly performs file/database write operations against a local Zotero SQLite file, but the manifest declares no required permissions or equivalent guardrails. That mismatch can cause the agent platform to under-classify the skill's risk and invoke a database-modifying capability without explicit user/admin acknowledgement.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation text is broad enough to trigger on many natural-language requests related to Zotero organization or editing, increasing the chance the skill runs in situations where the user did not intend direct database writes. Because this skill modifies a live SQLite database, accidental invocation can lead to unintended metadata changes, note insertion, or item creation.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal