worldbank-al

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for using public World Bank data, with no evidence of hidden execution, credential collection, or destructive behavior.

This appears safe to install for agents that need World Bank public indicator data. Verify the separate worldbank-mcp server before enabling it, keep the environment empty unless you intentionally set non-secret tuning values, and remember the generic passthrough should be used only for World Bank API endpoints.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal