The Vibe VC

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed helper for submitting startup information to The Vibe VC, with consent warnings and no evidence of hidden, destructive, or persistent behavior.

Install only if you intend to disclose startup and contact information to The Vibe VC. Before running the helper, use --dry-run to review the payload, confirm the base URL, avoid secrets or private personal data, and choose least-privilege integration access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill explicitly instructs use of a bundled CLI script to make external API calls and references environment-based configuration, yet the skill declares no permissions. This creates a transparency and policy-bypass risk because a caller may not realize the skill needs network and environment access before it attempts external disclosure or reads configuration such as VIBEVC_BASE_URL.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal