Back to skill

Security audit

Jlc Eda Drawing

Security checks across malware telemetry and agentic risk

Overview

The skill is a Markdown-only EasyEDA design copilot whose command and bridge needs are broadly aligned with its stated purpose, though its documentation overstates cleanup and references files not included in the artifact.

Install only if you are comfortable granting local command execution for EasyEDA automation. Because the referenced bridge script and reference files are absent from the artifact, review any bridge package or commands the agent proposes before running them, especially when working on important design files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill metadata claims risk code and external dependencies were removed, but the skill still requests the powerful `exec` tool and references a bridge server script for controlling a local EasyEDA client. That mismatch is security-relevant because it can mislead reviewers and users into underestimating the trust and execution boundary, increasing the chance that command execution is granted without appropriate scrutiny.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.