Back to skill

Security audit

Trending Topic Analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill appears non-destructive, but its advertised real-world trend analysis is materially broader than the included script, which generates random simulated reports.

Review this before installing if you need real marketing or reputation intelligence. Treat its reports as synthetic/demo output unless the publisher adds real data collection, source provenance, and clear credential/platform access disclosures.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
76% confidence
Finding
The skill advertises generation of an output report file and the analyzer detected file-write capability, but the manifest does not declare corresponding permissions or clearly communicate that local files will be created. Undeclared write behavior reduces transparency and can surprise users or downstream systems that rely on permission metadata to sandbox skills safely.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill claims broad cross-platform tracking, sentiment analysis, propagation prediction, competitor comparison, and visualization, but the finding indicates the actual implementation uses random or templated data and does not perform the promised collection or analysis. This is dangerous because users may make business, marketing, or reputational decisions based on fabricated results presented as real intelligence.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill describes scraping multiple platforms and using an API key, but it does not warn users about data collection, credential handling, or platform access implications. Lack of disclosure can lead users to provide secrets or authorize collection without understanding operational, privacy, or compliance risks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.