Smart Scheduler

Security checks across malware telemetry and agentic risk

Overview

Smart Scheduler is a local meeting-scheduling helper that stores meeting details and exports calendar files as disclosed.

Install only if you are comfortable storing meeting and participant details in a local runtime database. Use the default ICS export location or choose output paths deliberately, since the helper writes calendar files where instructed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill invokes a Python helper script that reads and writes a local database and exports ICS files, yet the manifest declares no permissions. That mismatch weakens security review and policy enforcement because consumers may trust the skill to be non-privileged while it actually has shell execution, filesystem access, and potentially network-capable Python available.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal