Massive.com CLI

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Massive market-data API helper, but the published bundle is missing the main script it instructs agents to run.

Do not install this bundle as-is. Ask the publisher to provide a complete package including scripts/massive, then review that executable’s API-key handling, SecretRef exec support, logging redaction, and allowed network destinations before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill explicitly instructs agents to run a bundled Bash CLI (`scripts/massive`) and shell commands, but the manifest shown in SKILL.md does not declare any corresponding permissions. Undeclared shell capability increases risk because downstream systems or reviewers may treat the skill as less privileged than it really is, reducing scrutiny around command execution, network access, and secret handling.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal