Luca Assistant

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed credit-card rewards helper that installs a local MCP tool and stores portfolio records locally for its stated purpose.

Install only if you trust the luca-assistant PyPI/GitHub project. Expect setup to download and run that package, create a local database, fetch public card data, and retain any portfolio details you add for future recommendations and 5/24 checks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill exposes portfolio-changing operations such as adding and closing user cards, and it states that data is persisted in a local database, but it does not warn that these actions make lasting changes to personal financial profile data. This is risky because an agent could modify or overwrite sensitive user portfolio records without clear confirmation, leading to privacy issues, inaccurate 5/24 calculations, or unintended state changes.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal