Auxiliar Solve

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed tool-ranking helper, with the main risk being that it encourages installing an external MCP package and follow-on tools.

Install this only if you are comfortable letting your agent add and query the `auxiliar-mcp` package. Review any returned install commands before running them, prefer a sandbox for document-processing tools, and avoid giving cloud API keys or sensitive documents to recommended services unless you have checked their trust, cost, and data-handling terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation criteria are broad enough to activate this skill for generic situations like capability gaps or tool selection, which can cause an agent to install and rely on an external MCP service more often than necessary. In a security-sensitive environment, overly eager routing to a tool-installation skill increases attack surface, dependency risk, and the chance of unreviewed external tooling being introduced into workflows handling documents or web content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal