Volcengine Knowledge Search

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a disclosed API helper whose network, environment-variable, shell, and temporary-file behavior fits its stated purpose.

Install only if you are comfortable giving the skill its API key and allowing it to send your queries to the external service and write temporary local output. Prefer a dedicated API key, review generated temp files, and avoid using sensitive inputs unless you trust the service endpoint.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill invokes a Python script and explicitly documents capabilities such as network access, local file writing, shell execution, environment-variable use, and reading saved temp files, yet the manifest declares no permissions. This creates a trust and policy gap: a host may treat the skill as low-privilege while it can still reach external services and persist data locally, increasing the risk of unintended exfiltration, unsafe file handling, or bypass of operator review.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal