Back to skill

Security audit

Enterprise AI Opportunity Advisor

Security checks across malware telemetry and agentic risk

Overview

This skill performs the enterprise AI assessment and local report generation it advertises, with no evidence of hidden exfiltration or destructive behavior.

Install only if you are comfortable having the agent analyze the company materials you provide and save local report artifacts. Prefer redacted or summarized inputs for personal data, trade secrets, regulated data, customer records, credentials, and production details, and review the generated reports before sharing them externally because they include fixed Xixisys contact links.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill declares no permissions while its instructions require environment access, file reads/writes, and shell execution to render reports. This creates a transparency and consent gap: a user or platform may believe the skill is analysis-only, while it actually performs local operations that can access data and create artifacts.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The documented purpose emphasizes enterprise assessment, but the behavior also includes report generation, browser-based PDF rendering, and mandatory insertion of vendor contact/marketing details not central to the stated assessment function. This mismatch can mislead users about what the skill will do and can conceal data handling, promotional output, or external-link insertion in supposedly evidence-bounded reports.

Missing User Warnings

Low
Confidence
83% confidence
Finding
The skill instructs writing diagnosis and report files to disk without warning the user or obtaining explicit consent. In enterprise contexts, these artifacts may contain sensitive business information, and silent persistence increases the risk of unintended local data retention or exposure.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This intake questionnaire explicitly solicits sensitive categories such as personal information, trade secrets, R&D/production data, security audit requirements, and data residency constraints, but it provides no confidentiality notice, minimization guidance, or warning not to paste regulated or unnecessary raw data. In the context of an AI opportunity assessment skill, users may overshare sensitive enterprise data into the tool, creating privacy, compliance, and information exposure risk even if the questions are operationally relevant.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.