Back to skill

Security audit

Aicoo Discover

Security checks across malware telemetry and agentic risk

Overview

This skill is a real Aicoo Square discovery helper, but it also gives agents credentialed ways to chat, connect, and send friend requests with too little scoping for those account-affecting actions.

Install only if you want an Aicoo Square networking assistant, not just a read-only people search tool. Before use, require the agent to ask for explicit confirmation before any chat, connect, friend request, or batch action, and only provide API keys if you are comfortable with it changing your Aicoo network relationships.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is presented as a discovery/search tool, but it also instructs the agent to initiate chats and perform network connection actions. That creates scope creep from read-only discovery into outbound interaction and account-affecting behavior, which can lead to unauthorized contact or social graph changes without clear, specific user consent.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The skill includes account-modifying social actions such as instant connect and friend requests even though its stated purpose is only to discover people. These actions can alter the user's account state and relationships, making accidental or overly broad invocation materially harmful.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Although search is described as public, the skill also relies on bearer-token credentials for privileged network operations. Mixing public discovery with privileged authenticated actions increases the chance that a broad discovery trigger results in sensitive API use or unintended writes using the user's credentials.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad and overlap with common requests like finding people, collaborators, or contacts. Because this skill also contains action-capable follow-ons, broad matching increases the risk that it activates in contexts where the user did not intend Square discovery or any downstream interaction.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Auto mode is defined to infer intent from memory, repo files, and conversation context whenever the user has not provided an explicit query. That makes activation and search criteria ambiguous, increasing the chance of unrequested profiling and searches based on sensitive context rather than clear user direction.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes chat, connect, batch connect, and friend-request actions without a strong user warning that these are account-affecting or outbound interactions. Users may reasonably expect discovery to be passive, so missing warnings raise the risk of unintended social or reputational consequences.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.