Back to skill

Security audit

company-search-tool-free

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a company lookup helper, but its routing and capability descriptions are broader and less consistent than its query-only free-edition purpose.

Review before installing. Use this only for enterprise/company information lookup, and avoid letting it trigger for SEO or generic automation tasks. Confirm what Node.js script will be executed, whether it sends queried company or person names to an external service, and whether a private FN_API_KEY is needed. Treat the risk-screening and create/export claims as unclear until the publisher fixes the documentation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill documentation says the free edition does not support risk screening, yet the tool map lists risk-related queries such as executed person, dishonest, business anomaly, and administrative penalty. This inconsistency can mislead users or higher-level agents into invoking sensitive screening features unexpectedly, weakening policy enforcement and trust boundaries around what the skill is supposed to do.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The capability coverage text says the skill supports create/query/export operations, but the rest of the file presents the skill as query-only. In an agent ecosystem, overstating supported actions can cause unintended execution paths or unsafe assumptions about side effects, especially when the skill exposes exec-capable tooling.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The description is broad and generic enough to match many development scenarios without clear trigger boundaries. In agent routing contexts, this can lead to over-invocation of a skill that has exec access and embedded external-query behavior, increasing the chance of accidental or inappropriate use.

Vague Triggers

High
Confidence
97% confidence
Finding
The capability scope includes broad SEO/search-ranking keywords unrelated to the core enterprise-query function, which can cause the skill to activate for unrelated user requests. Because the skill also declares exec tooling, overbroad routing materially increases the risk of unintended command execution or unnecessary exposure of built-in external access.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The examples execute external commands and appear to query external services without warning the user that local code will run and company names will be transmitted outside the process. In a reusable skill, this can lead to unintended data disclosure or unsafe adoption by developers who assume the sample is purely local or inert.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.