Back to skill

Security audit

Facetory 表盘开发

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Facetory watchface workflow helper with disclosed local MCP editing and a narrowly scoped, permission-gated root fallback for asset import problems.

Before installing, understand that this skill can direct an agent to modify, save, and export the active Facetory project through a local MCP server. The Android root fallback should only be allowed for a specific asset file you choose, after reviewing the exact command, source, destination, overwrite behavior, and risk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The guidance explicitly recommends copying files into an app-private `/data/data/...` directory once 'root authorization' is obtained, but it does not require explicit per-action user confirmation, scope limitation, or warn about the sensitivity of privileged filesystem access. In a skill that automates MCP-driven project and asset workflows, this can normalize use of root to bypass normal storage boundaries and may lead to unauthorized file access, data exposure, or accidental modification of protected app data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
agents/openai.yaml:11