旅行疫苗指南

Security checks across malware telemetry and agentic risk

Overview

This travel health skill is not malware-like, but it should be reviewed because it presents static vaccine guidance as public-API data.

Install only if you are comfortable treating it as a static reference tool, not an authoritative or current travel medicine source. Verify vaccine requirements and health risks with official health agencies or a clinician before travel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill declares that it directly accesses public APIs, which implies outbound network use, but no corresponding permission declaration is present. This creates a transparency and governance gap: users and the platform may not be able to accurately assess or restrict data egress, and undeclared network capability can hide future expansion into more sensitive remote interactions.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill claims its vaccine guidance is based on public API data, but the finding indicates it actually relies on hardcoded local data. For a health-related skill, this is dangerous because users may trust the freshness and authority of recommendations that could be stale, incomplete, or inconsistent with current entry requirements or disease risks, leading to harmful travel health decisions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal