Back to skill

Security audit

Chemvision

Security checks for vulnerabilities and agentic risk

Overview

The skill is a chemistry helper, but its privacy and runtime disclosures are inconsistent enough that users should review it before installing.

Install only if you are comfortable with chemical names, SMILES strings, reaction inputs, or safety queries potentially being sent to PubChem/OPSIN through the local service. Do not use it for confidential research compounds unless the publisher clarifies network behavior or provides an offline/local-only mode.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill claims chemistry data 'never leaves the machine' while also stating it calls PubChem and OPSIN, which are external services. This is a material misrepresentation of data flow that can mislead operators into sending potentially sensitive chemical queries off-host without informed consent, creating privacy, compliance, and trust risks.

Static analysis

No suspicious patterns detected.