Back to skill

Security audit

Sync DeBox Docs

Security checks across malware telemetry and agentic risk

Overview

This skill coherently mirrors public DeBox documentation into a user-chosen folder and does not show hidden collection, credential use, persistence, or destructive behavior.

Install only if you want an agent to fetch public DeBox documentation and write a local mirror. Choose a dedicated empty folder for the output, expect outbound requests to docs.debox.pro and to links/images referenced by those docs, and review generated summaries as untrusted reference material rather than executable instructions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill directs the agent to perform file reads, file writes, and network access, but it declares no corresponding permissions or trust boundaries. That mismatch can cause the skill to run with broader effective capabilities than reviewers or users expect, reducing transparency and making unintended data access or remote content ingestion harder to evaluate safely.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.