Back to skill

Security audit

New Relic CLI Skills

Security checks across malware telemetry and agentic risk

Overview

This New Relic skill is coherent and disclosed, but users should be careful with its write and delete alert-management commands.

Install this only for New Relic accounts you intend the agent to inspect or manage. Use the least-privileged New Relic key and account scope available, review write commands before execution, and take special care with alert policy/channel creation and alert condition deletion. Be aware that New Relic CLI profile setup can store credentials and change the default profile on the machine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill clearly documents use of the New Relic CLI against remote APIs, which implies network access, but the file does not declare permissions for that capability. Missing permission declarations weaken review and enforcement boundaries, making it easier for a skill with API-key-backed access to contact external services without explicit governance. In this context, the risk is elevated because the skill supports both read and write operations against observability and alerting resources.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill documents a destructive command to delete an alert condition without any warning about irreversible impact, verification steps, or safer alternatives. In an agent-assisted context, this increases the chance of accidental operational damage such as disabling production alerting coverage, which can delay detection of outages or security incidents.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.generated_source_template_injection

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
deployments/SKILL.md:52