Back to skill

Security audit

Competitor Show Tracker

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Lensmor API workflow for ranking competitor trade-show matches, with paid lookup and activity-log side effects that require user approval before use.

Install only if you are authorized to use the Lensmor API key and accept that successful searches may spend credits, create API activity records, and update the API-key owner's HubSpot last_search_date. Do not use a shared or third-party key unless that owner has approved these side effects.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to obtain user approval for API calls that will also create a CRM-side effect by logging search activity and updating HubSpot metadata. Even though disclosed, this goes beyond pure event ranking and can write to external systems unrelated to the immediate user request, creating privacy, consent, and auditability concerns if the user is not the API-key owner or lacks authority over that CRM record.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The example output states that successful lookups will update HubSpot `last_search_date`, introducing a CRM write side effect that is unrelated to the skill's advertised purpose of ranking trade shows by competitor presence. Even in documentation, this normalizes hidden state changes and could lead users or implementers to trigger customer-record modifications without clear consent, creating privacy, integrity, and scope-creep risks.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
A competitor-show-ranking skill should be contextually read-oriented, so documenting HubSpot record updates is a capability mismatch that makes the behavior more dangerous, not less. This kind of unexpected write access can be abused to alter CRM metadata, create misleading activity trails, or silently enrich records under the cover of an unrelated workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.