Back to skill

Security audit

dimos-robotics-skill

Security checks across malware telemetry and agentic risk

Overview

The skill appears to provide disclosed engineering guidance for robotics/code workflows, with only a permissions-documentation gap noted by the scanner.

Install only if you want an agent to help with robotics or ROS-style engineering work. Review generated code before applying it to real hardware, prefer simulation first, and require explicit confirmation before file changes, shell commands, deployment, or any live robot operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding
The skill exposes operational guidance for MCP interaction and code-generation workflows, and the analyzer detected file-write and MCP-capable behavior without any explicit permission declaration. In an agent skill system, undeclared capabilities weaken policy enforcement and user awareness, which can allow the skill to create/modify files or interact with MCP tools in ways the operator did not explicitly approve.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.