Review Summarizer

Security checks across malware telemetry and agentic risk

Overview

This skill is non-destructive, but it advertises live multi-platform review scraping while the code actually uses canned demo reviews, which could mislead users making buying or business decisions.

Install only if you understand this as a demo/template or plan to verify and replace the scraping implementation. Do not rely on its summaries for purchases, arbitrage, or affiliate content unless you confirm the data source is real and current, and choose output paths carefully to avoid overwriting files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill documentation advertises scripts that read from local inputs and write outputs to user-specified files, but the skill declares no corresponding permissions. That mismatch is a real security issue because agents or users may invoke file-capable workflows without an explicit trust boundary, increasing the chance of unintended file access or overwriting files in the local environment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal