Back to skill

Security audit

Lease Review

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Taiwan lease-review helper with a disclosed local report script and no evidence of hidden data sharing or harmful behavior.

Install only if you are comfortable having your local agent process lease details that may contain names, addresses, and financial terms. Use explicit input and output paths, review the generated report before relying on it, and treat the legal content as assistance rather than a substitute for professional legal advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding
The skill advertises executable capabilities via `python3` and instructs users to run local scripts, but it declares no explicit permissions despite clearly implying file read/write behavior through contract input processing and report output generation. This creates a transparency and least-privilege problem: users or hosting platforms may not realize the skill can access local files or generate artifacts, increasing the chance of unintended data exposure when reviewing sensitive lease documents.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.