Back to skill

Security audit

Science Research Writing

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent research-writing helper that reads its own guidance files and user-supplied manuscript materials without hidden, destructive, or unrelated behavior.

Before installing, expect the skill to inspect the research materials you provide and possibly run local validation scripts on draft/model files. Do not provide confidential manuscripts, datasets, or target papers unless you are comfortable having the agent use them for the requested writing task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs the agent to read multiple local files such as references, assets, and scripts, which is a form of file-reading capability, but no explicit permission declaration is present. In an agent framework, undeclared file access can expand the skill's trust boundary and may allow unintended access to workspace contents if file resolution is not tightly sandboxed.

VirusTotal

48/48 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.