Back to skill

Security audit

Knowledge Graph

Security checks across malware telemetry and agentic risk

Overview

This skill appears to manage a local workspace knowledge graph without signs of hidden data access, networking, or destructive behavior.

Install this if you want an agent to maintain local knowledge-graph files under life/areas. Review or back up those files if they matter, and prefer a version that explicitly declares its file read/write scope.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill clearly instructs the agent to read and write repository files under `life/areas/**`, but it does not declare any permissions. This creates a permission-transparency gap: callers or policy layers may assume the skill is lower risk than it actually is, while it can modify persistent knowledge-graph data and potentially overwrite or poison files if invoked improperly.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.