Mx Search

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward financial-search helper that contacts a disclosed Meixiang API, with privacy cautions but no evidence of hidden or harmful behavior.

Install only if you trust the Meixiang API provider. Use a dedicated API key if possible, avoid putting secrets, account details, personal data, proprietary research, or nonpublic investment information in queries, and delete saved JSON results when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs sending the user's query directly to a third-party financial search API but does not warn that user-supplied content will leave the local environment. If users include sensitive investment intent, account details, nonpublic information, or proprietary research terms in their queries, the skill could disclose that data to an external service without informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal