Back to skill

Security audit

research-gap-finder

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says: it searches public scholarly APIs and saves research-gap project files without hidden credential use, background persistence, or destructive behavior.

Install only if you are comfortable sending research queries to the listed scholarly services and storing API response caches in the chosen project directory. Avoid using proprietary or sensitive research material with the optional guided browser tools unless you have checked those services' terms and privacy posture.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill advertises and instructs use of file I/O, shell execution, and broad outbound network access, but the only declared metadata shown is under a custom `openclaw` block rather than an explicit permissions model. That mismatch can cause the platform or reviewers to underestimate the skill's effective privileges, making it easier for a user to run a networked CLI that writes local artifacts and invokes external binaries without clear consent boundaries.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.