Back to skill

Security audit

Box Automation

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a legitimate Box automation helper, but it gives agents broad cloud-file powers without enough safety guidance for deletion and sharing.

Install only if you are comfortable giving the agent access to your Box account through the configured MCP. Before using it, require the agent to confirm exact file or folder IDs, recipients, sharing settings, and any recursive or permanent deletion. Prefer trash or reversible actions over permanent removal, and avoid public links unless explicitly intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill documents destructive folder operations such as delete and permanent removal, but it does not instruct the agent to obtain explicit confirmation, warn about irreversible consequences, or verify authorization before acting. In an automation context, this omission increases the risk of accidental or socially engineered data loss, especially because the skill normalizes recursive deletion and permanent removal as standard workflow steps.

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill describes uploading, downloading, and sharing Box content without warning that these actions transfer potentially sensitive data to and from external cloud storage or may expose data through shared links and collaborations. In an agent setting, the lack of privacy and data-handling guidance makes accidental exfiltration or oversharing more likely when operating on user files.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.