Back to skill

Security audit

Office Productivity

Security checks across malware telemetry and agentic risk

Overview

This office automation skill includes ordinary document scripts, but it also advertises broad email and calendar control without clear scoping or user-confirmation safeguards.

Use this skill only for document/PDF generation unless you can review and constrain any email or calendar workflow yourself. Do not provide IMAP, SMTP, or calendar credentials unless the missing implementation is supplied and every send, reply, archive, bulk file change, or calendar update requires explicit approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding
The skill advertises file-creation and document-generation capabilities but does not declare corresponding permissions. This creates a transparency and governance gap: users and hosting systems may not realize the skill can write or modify files, increasing the chance of unintended file changes or misuse in automated workflows.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger scope is extremely broad, covering essentially any office-efficiency task. Overbroad triggers can cause the skill to activate in contexts involving sensitive documents, email, calendars, or file operations without sufficiently clear user intent, increasing the risk of accidental high-impact actions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill includes reading/sending email and creating calendar events but provides no privacy, consent, or account-impact warning. These actions can expose sensitive communications, send unintended messages, or modify schedules, which is especially risky in a broadly triggered office automation skill.

Missing User Warnings

Low
Confidence
76% confidence
Finding
The skill describes batch file processing and document/PDF modification without warning that files may be changed, overwritten, merged, or transformed. In office workflows, silent file-changing behavior can lead to data loss, corruption, or unintended edits at scale, especially during batch operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.