Back to skill

Security audit

Operational Director

Security checks across malware telemetry and agentic risk

Overview

This skill reads a packaged demo business snapshot to summarize operational status and does not show hidden network access, data mutation, or destructive behavior.

Install this only if you want a Russian-language business-summary assistant that uses the bundled test/mock snapshot. Treat its financial output as demo/test information, not real bank data, and be aware that replying with 1, 2, or 3 after its suggestions may continue the summary flow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill instructs the agent to run a local Python script and explicitly claims access to local data, which implies filesystem read capability, but the declared permissions only mention a binary requirement and omit an explicit file-read permission. This mismatch weakens security review and user consent because the skill can access local snapshot data without transparently declaring that capability.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill allows follow-up activation from bare numeric replies '1/2/3', which are highly ambiguous and commonly used across unrelated conversations. This can let the skill seize control of subsequent turns based on minimal input, especially after any prior enumerated list, and may trigger access to sensitive local business data without clear user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill allows follow-up activation from bare numeric replies '1/2/3', which are highly ambiguous and commonly used across unrelated conversations. This can let the skill seize control of subsequent turns based on minimal input, especially after any prior enumerated list, and may trigger access to sensitive local business data without clear user intent.

Vague Triggers

Medium
Confidence
79% confidence
Finding
The default prompt is very broad and provides little constraint on when or how the skill should be invoked, which can cause over-triggering for loosely related business questions. In a business-operations skill that may summarize sensitive financial and operational state, underspecified invocation increases the chance of inappropriate use, overcollection of context, or misleading authoritative responses outside the intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.