Back to skill

Security audit

Alibabacloud Migration Mas Cloud Migration Survey

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a migration-report generator, but it needs review because it can automatically create reconstructed source files at user-provided paths without asking first.

Review before installing if you need strict auditability. Use it only where automatic report generation is acceptable, and avoid referencing paths where creating a new .xlsx/.docx/.csv/.txt file would be surprising. Treat reports generated from reconstructed missing files as drafts, not authoritative source evidence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
The skill claims to only organize user-provided materials, but it also instructs autonomous reconstruction of missing source files and creation of intermediate artifacts. That mismatch can cause operators and users to trust the skill with a narrower data-handling model than it actually has, increasing the risk of unintended file creation, provenance confusion, and reports derived from synthetic rather than real evidence.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
Autonomously reconstructing a missing input file changes the trust boundary from passive summarization to active content generation at a user-supplied path. This can lead to fabricated or incomplete source artifacts being treated as authoritative inputs, weakening auditability and creating opportunities for accidental data integrity issues or misuse in downstream workflows.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.