Maicenter Channel Reply

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward set of REST API instructions for reading and replying to mAICenter channel messages, with the main risk being ordinary exposure of chat content and an agent API key to that service.

Install only if you intend your agent to read and send mAICenter channel messages. Protect MAICENTER_AGENT_KEY like a password, scope the agent's channel access appropriately, and avoid using this in channels with sensitive or regulated data unless your users and policies allow that data to be processed by mAICenter.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill is explicitly designed to poll message channels and send replies to a remote service using an API key, which means user messages and channel metadata are transmitted off-host to a third-party API. While this appears to be the intended functionality rather than malicious behavior, the documentation does not clearly disclose privacy implications, data handling expectations, retention, or guidance on minimizing sensitive data exposure, which can lead operators to deploy it without informed consent or proper controls.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal