Wall Mounted Faucet Layout

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused faucet-geometry calculator and diagram generator with behavior that matches its stated purpose.

Before installing, note that this skill can run local Python scripts and can create an SVG file when you ask for a diagram. Use a clear project output path for generated diagrams, and treat the geometry as an estimate that still needs on-site validation before installation work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill instructs the agent to generate an SVG and explicitly write it to disk via an output path, but the skill metadata does not declare any corresponding file-write permission. This creates a capability/permission mismatch: an agent may perform filesystem writes that are not surfaced to policy or users, increasing the risk of unintended overwrites or writing to sensitive/user-visible locations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal