Back to skill

Security audit

Mcp Builder

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent MCP server-building guide with optional evaluation scripts, but users should avoid running evaluations against sensitive data unless they are comfortable sending results to an external model and saving them in reports.

This is reasonable to install as a development aid. When running the evaluation harness, only use read-only evaluation tasks, point it at MCP servers you trust, and avoid secrets or highly sensitive business data because tool outputs are sent through Claude during evaluation and may be summarized in the generated report.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Ssd 3

Medium
Confidence
97% confidence
Finding
The evaluation prompt explicitly instructs the model to include tool inputs and outputs in the summary and feedback. If tools process secrets, personal data, tokens, internal documents, or privileged API responses, that data can be echoed into the final evaluation report and then printed or saved to disk, creating a clear secondary disclosure channel.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.