Plati MCP Search

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Plati marketplace search helper, with the main caution being that it depends on a separate npm MCP server package.

Install this only if you trust the external `plati-mcp-server` npm package and are comfortable adding a local MCP server. Review or pin the package version where possible, do not provide private account details in marketplace searches, and verify seller terms carefully before buying subscription offers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill hard-codes Russian-language output ('Название', 'цена', 'Проверено...') regardless of the user's language or consent. This can mislead users, degrade usability, and create social-engineering or compliance risks if the agent responds in an unexpected language, especially for purchases or pricing decisions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal