Back to skill

Security audit

Chromecast Control Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill mostly does Chromecast control as advertised, but its activation instructions incorrectly tell agents to use it for database and SQL tasks, which could cause unrelated requests to trigger local network and media-control commands.

Review this skill before installing. Its Chromecast commands are generally purpose-aligned, but the trigger text should be corrected to Chromecast-only tasks before use. Run it only on trusted networks, confirm before scanning the LAN or casting local files, and avoid exposing sensitive local media through temporary HTTP serving.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The trigger conditions state the skill should be used for database operations and SQL/storage management, but the skill actually performs Chromecast discovery and media casting. This mismatch can cause the agent to invoke the skill in unrelated contexts, leading to unintended network scans or media-control actions on local devices.

Vague Triggers

High
Confidence
98% confidence
Finding
The activation guidance is inconsistent with the documented functionality, making the skill eligible for ambiguous or incorrect invocation. In an agent system, such scope confusion is dangerous because it can cause execution-capable tooling to run network-affecting commands in response to unrelated user requests.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes device discovery and local-file casting without clearly warning that these actions scan the local network and may expose local media via a temporary HTTP server. Users may unknowingly disclose device presence, IP addresses, or local content to others on the same LAN.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.