Back to skill

Security audit

设计

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a MongoDB helper, but its documentation and permissions broaden into generic file, API, and command execution without clear scoping or user controls.

Review this skill before installing. It is not evidence of malware, but it asks for powerful agent capabilities and describes broad automation beyond MongoDB. Use it only where file writes, API calls, and shell commands are acceptable, and require explicit confirmation for any database mutation, local file change, or command execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a MongoDB-focused assistant, but the documentation broadens its capabilities to generic file processing, API integration, and system command execution. This scope expansion can mislead users and downstream agents into granting or invoking powerful operations unrelated to the stated purpose, increasing the chance of unsafe file, network, or shell actions under a trusted database-oriented label.

Description-Behavior Mismatch

Low
Confidence
86% confidence
Finding
The input/output contract describes a generic automation pipeline with vague steps and generic execution logs rather than MongoDB-specific operations. This ambiguity can enable overbroad interpretation by an agent, causing it to perform unintended actions outside the expected database context while users believe they are invoking a narrowly scoped MongoDB helper.

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The document mixes a MongoDB skill description with unrelated premium features like high-resolution output, style presets, and model fine-tuning. Such contradictory content signals template contamination or deceptive packaging, which undermines trust in the declared function and may hide the true operational scope of the skill or its side effects.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises file writing, external API integration, and command execution, but does not provide clear user-facing warnings about modification of local files, outbound data transfer, or system-level effects. In a skill named and described as MongoDB-focused, these powerful capabilities create a risk of unexpected data exfiltration, destructive changes, or unsafe command execution if users or agents trust the narrow branding.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.