Baidu Pan Upload

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Baidu Pan upload helper that uploads a user-chosen local file using user-provided Baidu credentials.

Install only if you intend to run local Python/curl code that uploads selected files to your Baidu Pan account. Keep the .env private and out of version control, verify the remote directory before running, and use --overwrite only when replacing an existing cloud file is intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill explicitly instructs users to run a Python upload script that uses both shell execution and outbound network access, but the skill declares no permissions or capability boundaries. This creates a transparency and least-privilege problem: an agent or user may invoke code with broader effects than the manifest communicates, including uploading local files and using credentials from a .env file.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal