Naver Real Estate Search

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: it searches and monitors Naver real-estate listings, with disclosed network use and local JSON state files.

Before installing, confirm you trust or have inspected the local tmp/naverland-scrapper dependency, and avoid putting unnecessary personal details into search queries. Review or clear watch-rules.json and candidate-cache.json if saved property interests or alert thresholds are sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill clearly documents capabilities to read and write local files and access the network, but it does not declare permissions or equivalent user-facing constraints. That creates a transparency and policy gap: a caller may invoke a skill that can persist watch rules, modify cache/reference files, and fetch remote data without an explicit permission boundary or informed consent model.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal