Back to skill

Security audit

实验数据集成本估算(Experiment Dataset Cost Estimation)

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed dataset-cost estimator that uses specialized biomedical MCP queries, with no hidden persistence or destructive behavior found.

Install only if you intend to use PatSnap/Eureka MCP and Office report generation for biomedical dataset-cost estimation. Confirm you are authorized to query PatSnap data, keep commercial patent/SAR outputs under legal review, and treat ADMET results as estimates rather than safety or experimental conclusions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill documents capabilities that imply file reads/writes, network access, and shell/office workflow execution, yet it declares no permissions. This creates a transparency and governance gap: a reviewer or execution platform may underestimate what the skill can do, allowing broader data access or artifact generation than expected.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The routing guide for a dataset cost estimation skill includes operational drug intelligence, patent mining, SAR extraction, and ADMET prediction workflows that materially exceed the declared scope. This creates a capability/scope mismatch: an agent invoked for budgeting could be steered into performing substantive biomedical discovery and competitive intelligence tasks, increasing the risk of unauthorized data processing, excessive tool use, and misuse of high-impact domain functions.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
ADMET prediction is a specialized scientific analysis capability, not a necessary component of simple dataset costing. Embedding it in this skill widens the attack surface and enables users to obtain compound triage or safety-related predictions under the cover of a budgeting workflow, bypassing intended separation of duties and scope controls.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The patent SAR submission and polling workflow performs iterative extraction of structure-activity data from patents, which is far beyond what is needed to estimate staffing or budget. In context, this enables the skill to conduct meaningful patent-derived chemical intelligence gathering, creating misuse potential and unnecessary exposure to compliance and data-governance risks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.