Back to skill

Security audit

ITjuzi

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent ITjuzi bulletin lookup tool, but users should understand that optional member tokens can be stored locally and partially shown by a status command.

Install only if you are comfortable using an ITjuzi Skill Token with this tool. Prefer the ITJUZI_SKILL_TOKEN environment variable for temporary use, avoid running the token status command in shared logs or transcripts, and remove the saved token when you no longer need member access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The documented behavior goes beyond simple bulletin querying and includes credential persistence, token inspection, and local credential sourcing, none of which are disclosed in the top-level purpose. This is dangerous because users may provide sensitive tokens without understanding they are stored persistently on disk and partially exposed through status commands, creating confidentiality and consent risks.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill goes beyond its stated purpose of querying IT桔子 telegraph data by implementing token storage, removal, and inspection commands. While not inherently malicious, this expands the attack surface and enables local credential handling features that are unnecessary for a read/query-oriented skill, increasing the risk of secret exposure or misuse.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The --show-token command reveals the first 20 characters of the bearer token and discloses whether it came from the environment or a local file. Even partial token disclosure materially weakens credential secrecy and can aid token theft, correlation, or debugging-output leakage in agent environments.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation instructs users to save a token permanently and says it will remain effective indefinitely, but it provides no meaningful warning about local secret storage, retention, access controls, or privacy implications. This can lead to credential exposure on shared systems, unintended long-term retention, and users unknowingly leaving sensitive access tokens on disk.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The script writes a bearer token to disk immediately when --set-token is used, without warning, confirmation, or any notice about persistence. Although file permissions are tightened, storing credentials on disk creates residual-secret risk, especially on shared systems, backups, or when users do not expect persistence.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.