Back to skill

Security audit

Táve

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed connector skill, with a caution that the short description sounds read-only while the body discusses possible write or destructive connector actions.

Install only if you trust the connector provider and intend to let the agent operate the connected service account. Treat the skill as potentially write-capable despite the read-oriented description, and require explicit confirmation before any action that creates, updates, deletes, posts, or changes account data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest and description tell users this skill is for 'searching and reading data,' but the body explicitly states that write and destructive actions may exist and can be run through the same skill. This creates a trust-boundary mismatch: callers, reviewers, or policy engines may classify the skill as read-only while it can actually perform state-changing operations if such actions are exposed by the connector.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.