Maverick Asana Mcp 2

Security checks across malware telemetry and agentic risk

Overview

This skill transparently connects an agent to Asana using OAuth, with disclosed ability to read and update Asana work when the user directs it.

Install only if you want the agent to act through your Asana OAuth grant. Use an appropriately scoped Asana account, confirm create/update/delete actions before they run, avoid sending unrelated sensitive data through Asana tool calls, and revoke the OAuth grant when you no longer need the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Unrestricted Tool Access

Medium
Category
Excessive Agency
Content
The output includes the server's `Instructions:` field (read it) and a JSON Schema for every tool's parameters. Treat this as the authoritative reference for the rest of the session.

**Step 2 - Call any tool from the catalog** using the form `maverick-asana.<tool>`:

```sh
mcporter --config {baseDir}/mcporter.json call maverick-asana.<tool> <arg>=<value> ...
Confidence
85% confidence
Finding
Call any tool

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal