Back to skill

Security audit

rankrat

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed SEO and search-analytics MCP wrapper whose sensitive read/write powers are purpose-aligned and gated by explicit configuration.

Install this only for sites and provider accounts you control. Keep the default read-only mode for reporting, bind HTTP to loopback or a private network with the bearer secret, and enable write, agent onboarding, or unbounded mode only for trusted sessions where you are comfortable with the connected agent submitting URLs, changing search-console/Bing resources, publishing DNS verification records, or updating the boundary file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
tools are absent from `tools/list` and the REST write routes are not mounted. An
agent cannot discover them, let alone call them.

Set it to `false` and they appear. There is no approval ID, admin API, or second
bearer token — the trusted caller gets direct access, with writes still confined
to the configured boundaries and to what the provider account itself permits.
Writes cover IndexNow submission, Bing URL/sitemap/property changes, Google
Confidence
86% confidence
Finding
no approval

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.