Back to skill

Security audit

meta-legal-assistant-pro

Security checks across malware telemetry and agentic risk

Overview

This legal-assistant skill is not clearly malicious, but it adds persistent learning and cross-session memory for sensitive legal use without tight scope or user controls.

Install only if you are comfortable with the skill keeping cross-session learning data. Avoid recording confidential legal facts or personal details unless storage scope, deletion behavior, and user consent controls are clarified.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises self-reflection, memory, and learner-style evolution, which implies state persistence and likely file writes, but it declares no permissions. Undeclared write capability is dangerous because it bypasses least-privilege review and can enable silent storage of user data, policy traces, or agent state in ways operators did not authorize.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The declared purpose is a China-focused legal assistant, but the behavior includes generic learning, persistent statistics, user preference storage, and reusable CLI-style optimization unrelated to the stated legal workflow. This mismatch is dangerous because it hides cross-context data collection and generalized persistence behind a narrower trust label, increasing the risk of undisclosed profiling, overcollection, and unintended reuse of sensitive legal-consultation data.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The module writes persistent state to whatever skill directory is supplied, with no restriction that the path belongs to the current skill or an approved workspace. In a multi-skill or shared environment, this expands the tool's authority beyond the legal-assistant context and can overwrite or create files in other skill directories, enabling cross-skill state tampering or unintended persistence.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.