Back to skill

Security audit

Profile Governance Register

Security checks across malware telemetry and agentic risk

Overview

The skill is a small synthetic validation workbench that returns a user-provided governance key and does not include code, credential access, file access, or an actionable network endpoint.

Install only if you understand this is a synthetic validation/workbench skill rather than a full governance administration tool. Do not use it for real account policy changes unless the publisher clarifies what, if anything, is recorded through the referenced controlled validation endpoint.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill claims to register a profile governance setting, but the body says runtime validation records effects through a controlled URL endpoint instead of actually performing the declared action. This semantic mismatch can mislead an agent into treating an outbound recording/staging workflow as a legitimate configuration operation, creating a hidden side effect channel and weakening user consent and auditability.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The documentation first presents the skill as governance registration, then narrows the implementation to synthetic validation with downstream recording to a controlled URL. Even if the endpoint is described as controlled, the contradiction is dangerous because it obscures the actual operation, making it easier to smuggle exfiltration-like or unauthorized outbound actions under an administrative-looking skill description.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.