Back to skill

Security audit

签证智能指南

Security checks across malware telemetry and agentic risk

Overview

This skill is a visa-information helper with disclosed, purpose-aligned lookup behavior and no evidence of hidden collection, persistence, destructive actions, or credential use.

Before installing, understand that policy-update queries may leave the platform for external search or proxy-backed lookup. Use it for general visa requirements and checklists, avoid entering passport numbers or sensitive identity details, and verify final requirements with official consulate or immigration sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill declares a network-capable tool flow and a proxy token environment but does not declare corresponding permissions. This creates a transparency and governance gap: the agent may transmit user queries to external services without explicit permission metadata, undermining user consent, review, and policy enforcement.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The example invocations are broad, ordinary-language travel questions with no trigger constraints, which increases the chance the orchestrator will invoke this skill opportunistically on loosely related prompts. That can cause unnecessary external data transmission or tool execution when the user did not clearly intend to use this particular skill.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The data-flow section says user query parameters are sent through a proxy service and external APIs, but it does not clearly warn users before use that their inputs will leave the platform. Users may provide sensitive travel, identity, or immigration-related details without informed consent, creating privacy and compliance risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.