Back to skill

Security audit

real-estate-autos-research

Security checks across malware telemetry and agentic risk

Overview

The skill is mainly aligned with home and car research, but its helper can call arbitrary Crawlora endpoints beyond that stated scope.

Install only if you are comfortable with a generic Crawlora API helper being available. Keep CRAWLORA_API_KEY private, monitor Crawlora credit usage, and use only the documented Zillow, Redfin, CarMax, Autotrader, and Cars.com endpoints unless you intentionally want broader Crawlora access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The helper script is a generic Crawlora client that accepts any path and method, while the skill is described as limited to real-estate and used-car research. That mismatch expands the skill's effective capability far beyond its declared scope, which can enable unintended data access or use of unrelated third-party endpoints through the same trusted skill surface.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:22