Context Crumb

Security checks across malware telemetry and agentic risk

Overview

ContextCrumb is a coherent local document-compression helper with disclosed, user-directed file reading and no detected malicious behavior.

Install only if you are comfortable using the ContextCrumb package on local documents. Use it for quick orientation on prose-heavy files, then check the original source before quoting, editing, copying commands, or making decisions involving sensitive or exact text.

Publisher note

ContextCrumb downloads public model weights from Hugging Face on first use and can optionally call a local warm HTTP service for repeated compression requests. The MCP server itself runs locally and only reads/compresses text or files requested by the client.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal