Back to skill

Security audit

alloy-composition-search-zhcn

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent alloy composition search assistant that uses a disclosed, purpose-aligned MCP integration without persistence or destructive behavior.

Before using this skill with confidential alloy formulas, unpublished R&D, or patent strategy, confirm whether calls to mace-mcp are acceptable in your environment because the skill may send relevant query details or derived composition parameters to that MCP service.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly states it can use an external MCP server for alloy retrieval and literature access, but it does not disclose that user queries, alloy descriptions, or derived structured composition data may be transmitted to that outside service. This creates a data transparency and privacy risk because users may provide proprietary materials formulations, R&D questions, or unpublished patent strategy information without realizing it will leave the local environment.

Static analysis

No suspicious patterns detected.