Appian Deploymtstatus

Security checks across malware telemetry and agentic risk

Overview

This Appian deployment-status skill is mostly purpose-aligned, but its optional artifact download can write outside the promised exports folder if a server supplies a crafted filename.

Review before installing if you will use --download-log or --download-zip. Use a least-privilege Appian API key, set APPIAN_BASE_URL only to a trusted Appian tenant, and avoid artifact downloads until filename handling is fixed or you fully trust the deployment response.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill documentation indicates use of environment variables and outbound network access, but no explicit permissions are declared. This creates a governance and least-privilege gap: the runtime may grant broader capabilities than users or reviewers expect, and the fallback to reading a local appian.json file increases the chance of unintentionally accessing sensitive credentials from disk. In a deployment-monitoring skill, network and secret access are expected functionally, but they still must be explicitly declared to prevent hidden capability creep.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal