Back to skill

Security audit

alist

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-aligned for AList cloud-drive management, but it needs Review because it can upload, share, delete, and track customer delivery data without clear user-control or retention guardrails.

Install only if you intentionally want an agent to operate your AList-backed cloud drives through the configured MCP server. Review the MCP server permissions, use a limited AList account where possible, and require confirmation before uploads, deletions, share-link creation, or customer delivery tracking.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill claims to manage cloud drives, upload files, generate shares, and track deliveries, but the provided artifact is only documentation and does not implement those behaviors. This mismatch can mislead users or higher-level agents into trusting nonexistent capabilities, causing unsafe delegation, incorrect assumptions about data handling, and possible routing of sensitive file-management tasks to an unverified integration.

Scope Creep

High
Confidence
98% confidence
Finding
The manifest declares only `read`, but the documentation advertises mutating operations such as upload, delete, share creation, and delivery tracking. This inconsistency is dangerous because it obscures the true authority needed by the skill, weakening permission transparency and making it harder for reviewers and users to understand the data-modifying and privacy-impacting actions involved.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are very broad (`文件上传/网盘分享/素材管理`) and overlap with many normal file-handling requests. Overbroad triggers increase the chance of accidental activation, which is more dangerous here because the skill describes potentially sensitive actions such as uploading content, generating share links, and managing external storage.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documentation includes deletion, file sharing, and buyer delivery tracking, all of which can affect user data and privacy, but it does not warn users or require explicit consent. In this context, silent handling of files and customer identifiers could lead to unintended disclosure, retention, or destructive actions against cloud-stored assets.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.