Back to skill

Security audit

sn-search-market-cn

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed China market-research helper that uses listed official public sources and a small CNINFO query script without signs of hidden persistence or data misuse.

Install this if you are comfortable with an agent browsing the listed official Chinese market and regulatory sites and running the CNINFO query helper. Do not provide login cookies, API keys, or personal sensitive data unless you have a separate reason and clear control over what will be sent.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill clearly instructs use of networked resources and an API script, yet no declared permissions are present. This creates a governance and transparency gap: the runtime may permit outbound access without an explicit permission boundary, making review, consent, and policy enforcement weaker.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.