Skill Security Scanner

Security checks across malware telemetry and agentic risk

Overview

This is a defensive skill scanner whose file reads, network fetching, and optional workflow hooks are disclosed and fit its purpose.

Reasonable to install as a defensive helper, but treat results as advisory rather than a guarantee. Only add the AGENTS.md policy or pre-commit hook if you want those ongoing workflow controls, and be cautious scanning untrusted remote ZIPs because malformed or oversized archives can still create operational risk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill advertises and instructs use of file reads, network access, and shell execution, yet declares no explicit permissions or capability boundaries in the metadata. For a security-scanning skill, these capabilities are expected, but the lack of declaration reduces transparency and can cause users or tooling to underestimate what the skill can do.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal