Back to skill

Security audit

Uplo Clinical

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-built for clinical organizational search, but it asks for broad sensitive access and remote API connectivity without enough scoping or user-facing safeguards.

Install only in an approved clinical or enterprise environment where the UPLO endpoint is trusted, the API token is least-privilege, HTTPS is enforced, and exports are limited, logged, and reviewed. Treat organization-wide exports and clinical searches as sensitive operations that may include PHI, PII, personnel data, and system inventory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The README advertises capabilities to search clinical documentation and export full organizational context, which strongly implies access to highly sensitive enterprise and potentially patient-related information. Presenting these features without any privacy, authorization, data-minimization, or compliance warnings increases the risk that users deploy or use the skill in ways that expose confidential business data or regulated health information.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill directs automatic retrieval of identity context, including clearance level and role-based access, at session start without user consent, minimization, or a warning that sensitive attributes will be accessed. In a clinical environment, this can expose workforce identity, authorization scope, and operational directives unnecessarily, increasing privacy risk and enabling over-collection of sensitive context before a user’s task is known.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill promotes exporting organization-wide clinical context, including personnel and active systems, without emphasizing sensitivity controls or restricted use. In a healthcare and clinical-trial setting, such an export can reveal internal structure, named personnel, and system inventory that materially aids reconnaissance, privilege targeting, or broader data exposure if used by an unauthorized or over-privileged user.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The manifest requires a secret API token and configures an HTTP-based MCP endpoint, but it provides no explicit user-facing warning that credentials will be sent to a remote service. In a clinical/pharma context, this increases sensitivity because the skill is designed to access organizational knowledge and may expose credentials or sensitive queries to an external endpoint if users do not clearly understand the network trust boundary.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.