Back to skill

Security audit

Venture Financing

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed agreement-template helper that may send entered contract details to a hosted Open Agreements service to generate DOCX files.

Before installing, decide whether agreement details are acceptable to send to the hosted Open Agreements MCP. Use the local CLI or preview path for confidential matters, and review generated agreements before signing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The workflow explicitly instructs the agent to send collected template field values to a remote MCP server for document generation, but the skill metadata and workflow do not require an explicit user-facing privacy notice or consent step before transmitting potentially sensitive financing and corporate data off-platform. In this context, the fields are likely to include confidential legal, investor, cap table, and company formation information, so silent transmission to an external service creates a real data exposure and compliance risk even if the remote service is legitimate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.