Back to skill

Security audit

Tariff Search

Security checks across malware telemetry and agentic risk

Overview

This is a coherent tariff lookup skill that sends product details to accio.com for classification, with no evidence of hidden persistence, credential access, or unrelated behavior.

Install only if you are comfortable sending product names, origin/destination country codes, and optional product metadata to accio.com for tariff classification. Avoid using it with confidential catalogs or unreleased sourcing plans unless that third-party processing is approved.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill clearly describes making external API requests to TurtleClassify, but the metadata shown does not declare corresponding network permissions. This creates a transparency and governance gap: users and policy enforcement systems may not be adequately informed that data leaves the local environment, which can lead to unintended external data exposure.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The workflow instructs users to send product records including origin, destination, and product names to an external TurtleClassify API, but the description does not prominently warn that this data is shared with a third party. In enterprise or regulated contexts, product descriptions and sourcing information may be sensitive, so silent transmission can cause confidentiality, compliance, or trust issues.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal