Back to skill

Security audit

code-right

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed remote document-generation client that sends user-provided project details to an external service and emails the resulting download link.

Install only if you are comfortable sending the system name, optional system description, recipient email address, and any supplied access token to softcraft.cloud for remote processing and email delivery. Avoid confidential project details unless you accept that transfer and verify the recipient address before running the helper script.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill clearly describes networked behavior such as contacting a remote service, creating backend tasks, and sending email/download links, yet no permissions are declared. This creates a transparency and consent problem: agents or users may invoke external network actions without an explicit permission boundary, increasing the risk of unintended data transmission.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill says it will email generated materials and a download link, but it does not present a prominent warning about external delivery of potentially sensitive documents. Users may provide confidential project names or descriptions without realizing the output will be stored remotely and distributed via email, which can lead to privacy, misdelivery, or unauthorized access issues.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.