Back to skill

Security audit

Tristan RFQ overseer

Security checks across malware telemetry and agentic risk

Overview

This RFQ workflow skill is coherent and disclosed, with manageable risks around configuring email and Telegram intake carefully.

Install only with a dedicated procurement vault and configured email/Telegram channels you trust. Use a dedicated inbox or folder rule for RFQs, review drafts before confirming sends, and avoid using it for highly confidential RFQs unless your vault and messaging retention policies are appropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding
The skill clearly describes reading from and writing to an Obsidian vault, but no explicit permissions are declared. That creates a trust and enforcement gap: operators may deploy it without realizing it can access local files, and platforms that rely on declared permissions cannot accurately constrain or review its behavior.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This skill processes potentially sensitive procurement data and stores it in an Obsidian vault while relaying notifications and drafts over Telegram and email, yet the user-facing description does not warn about those data flows. Missing disclosure increases the chance of inadvertent exposure of RFQ details, pricing, supplier information, or client data through channels that may not meet the user's confidentiality requirements.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The intake rule triggers on any inbound email whose subject or body contains generic terms like "RFQ" or "Quotation", which are common in ordinary business correspondence. In this skill, that can cause unintended creation of RFQ notes, downstream Telegram notifications, and propagation of untrusted email content into the procurement workflow, increasing the chance of workflow abuse or data pollution.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.