Back to skill

Security audit

Mcporter

Security checks across malware telemetry and agentic risk

Overview

This skill is a short, disclosed guide for using the mcporter CLI, with powerful actions that users should run carefully but no evidence of hidden or malicious behavior.

Install only if you intend to use mcporter. Review MCP server URLs and stdio commands before running them, use least-privilege accounts for OAuth, and check config changes because MCP tools can have side effects depending on the server.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs users to perform direct MCP calls, OAuth authentication, configuration edits, daemon control, and stdio execution, but it provides no safety guidance about credential handling, trust boundaries, or the fact that these actions may modify local config or interact with remote systems. In this context, the omission is risky because the skill normalizes potentially sensitive operations without warning users to verify endpoints, review arguments, or avoid exposing secrets in command lines and config files.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.