Back to skill

Security audit

Atlas Admin Console

Security checks across malware telemetry and agentic risk

Overview

This Atlas administration skill is not clearly malicious, but it asks for broad infrastructure-changing authority while its documentation is inconsistent and under-scoped.

Review before installing. Only use this with tightly scoped Atlas API keys, non-production testing first, explicit human approval for provisioning, user, allowlist, Terraform, and self-healing actions, and a verified source for any atlas-pro executable because the referenced script is not present in the artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The documented input/output schema describes a generic scoring or audit tool rather than an Atlas administration console, which is a strong sign of template splicing or deceptive repackaging. In a privileged admin skill, this mismatch is dangerous because users or agents may supply the wrong inputs, mis-handle outputs, or trust functionality that is not actually aligned with the stated operational scope, increasing the chance of unsafe execution or hidden behavior.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The '能力分类' section documents a generic category-processing action that does not fit the stated Atlas administration purpose. This inconsistency undermines operator trust and suggests the skill may have been assembled from unrelated fragments, which is risky in a tool that can perform privileged infrastructure actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill includes destructive and irreversible operations such as Terraform destroy guidance without a strong, prominent warning or approval gate. In an infrastructure admin context, even example commands can normalize unsafe execution and lead to accidental data loss or service disruption.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
Automatic scaling and self-healing actions are presented as straightforward automation without emphasizing that they can autonomously modify production infrastructure. In a MongoDB Atlas admin skill, this raises the risk of unintended cost increases, configuration drift, outages, or cascading operational changes if conditions are misconfigured.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The workflow examples create users, modify allowlists, and provision clusters without explicit safety warnings, least-privilege guidance, or approval controls. These actions directly affect access boundaries and production resources, so presenting them as routine workflow steps can enable accidental exposure or unauthorized operational changes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.