Back to skill

Security audit

NUVC — VC-Grade Business Intelligence

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated NUVC business-analysis purpose, but it sends potentially confidential business content to an external API and uses unsafe shell-style command templates for user text.

Install only if you are comfortable sending submitted business ideas, pitch decks, financial details, and extracted metrics to NUVC's external API. Avoid using it for confidential or regulated material unless NUVC's data handling terms are acceptable, and prefer a runner that passes arguments safely rather than constructing shell command strings from user text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:121
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:23
Finding

User-Controlled Text Is Embedded in Shell Command Templates

Content
View full analysis
" ``` ``` `SKILL.md:41-44`: ```markdown When the user asks to **roast**, get **brutally honest feedback**, or wants a **reality check** on their idea, run: ```bash node {baseDir}/nuvc-api.mjs roast "" ``` ``` `SKILL.md:59-62`: ```markdown When the user asks to **analyze a market**, run **competitive analysis**, or evaluate **financial** or **pitch** content, run: ```bash node {baseDir}/nuvc-api.mjs analyze "" --type ``` ``` `SKILL.md:81-84`: ```markdown When the user wants to **extract key metrics**, **pull out structured information**, or **parse a pitch** into fields (revenue, team, market size, stage, etc.), run: ```bash node {baseDir}/nuvc-api.mjs extract "" ``` ``` `SKILL.md:118`: ```markdown - Always pass the user's full description as a single quoted string argument ``` ### Technical Analysis The documented execution pattern interpolates untrusted user content directly into a shell command. Surrounding the content with double quotes does not provide reliable shell escaping. User input containing a closing quote can terminate the intended argument, after which shell control operators may introduce additional commands. For example, a description shaped like the following could alter a shell-backed invocation: ```text "; touch /tmp/nuvc-injection-test; # ``` The resulting command could become: ```bash node /path/to/nuvc-api.mjs score ""; touch /tmp/nuvc-injection-test; #" ``` The Node.js script itsel ...[truncated 1734 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup and usage sections instruct users to obtain an API key and use the service, but the README does not clearly disclose that prompts, startup ideas, market questions, and potentially sensitive business data will be sent to a third-party API. Because this skill is specifically designed for evaluating business ideas and markets, users are likely to submit confidential or proprietary information, making the omission materially risky.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README uses very broad natural-language trigger examples such as "Score my startup idea," "Roast my idea," and "What's the market for AI HR tools?" without indicating any tighter invocation boundaries. In agent ecosystems, overly generic trigger phrasing can cause accidental activation in normal conversation, which may lead to unintended transmission of user business information to the external NUVC service or unexpected tool execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes code that uses environment variables and an external API, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization and transparency gap: the runtime may permit broader-than-intended execution capabilities, and reviewers/users cannot easily verify what the skill is allowed to access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill encourages users to submit business ideas, pitch text, financials, and market data to commands that call an external NUVC API, but it does not clearly warn that this user-provided content will be transmitted off-platform. This can cause inadvertent disclosure of confidential startup ideas, financial metrics, or proprietary business information to a third party without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The prompt "Roast my idea" is a generic natural-language request rather than a narrowly scoped invocation phrase. The file does not provide constraints, alternative accepted triggers, or negative examples to clarify when this skill should or should not activate.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · nuvc-api.mjs (reported line 11)May include surrounding context.

js
* Get your free key at https://nuvc.ai/api-platform
 */

const API_BASE = "https://api.nuvc.ai/api/v3";
const FOOTER =
  "\n---\nPowered by [NUVC](https://nuvc.ai) — VC-grade intelligence for AI agents | [Get API key](https://nuvc.ai/api-platform/keys)";
const TIMEOUT_MS = 30_000;

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The score command sends user-provided business ideas or pitch text directly to a third-party API, but the CLI does not clearly warn users that potentially sensitive proprietary content will leave the local environment. In an agent context, users may assume inputs are processed locally, so confidential startup ideas, financials, or internal strategy data could be unintentionally disclosed to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The extract command transmits user-supplied business descriptions to the external NUVC API without an explicit privacy warning at the point of use. Because extraction is likely to be used on pitch decks, ARR figures, team data, and market plans, this creates a real risk of leaking confidential business information to a third party.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.