Back to skill

Security audit

Azure Gateway Cli

Security checks across malware telemetry and agentic risk

Overview

This skill describes a sensitive local Azure OpenAI gateway with API keys, caching, cost data, exec commands, and optional persistence, but its instructions and packaged contents are under-scoped and partly inconsistent.

Review this carefully before installing. Use it only in a controlled local environment, verify or obtain the missing server and service files from a trusted source, keep Azure keys in environment variables or a secret manager, bind only to localhost unless you add authentication, and avoid enabling the systemd service until you have a clear rollback plan.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documented output is a generic scoring/audit report and does not match the stated Azure gateway functionality. This kind of semantic mismatch can cause an agent to perform unintended review-style tasks or mis-handle gateway operations, increasing the chance of unsafe execution paths and operator confusion.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The input format requests generic review fields like content and strictness instead of operational gateway parameters. This mismatch can cause an agent to interpret arbitrary text as control input or route execution through the wrong logic, which is risky for a skill that exposes exec and local service management behavior.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes starting a local gateway, querying local HTTP endpoints, and registering a persistent systemd user service, but it does not clearly warn that this changes local system state and may expose sensitive traffic, keys, or cost data. In an agent context, unclear disclosure around service installation and local network behavior can lead users to authorize actions with broader persistence and privacy consequences than expected.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.