Back to skill

Security audit

Wyoming LLC Formation

Security checks across malware telemetry and agentic risk

Overview

This appears to be a Wyoming LLC guidance skill with documentation quality issues, but no hidden access, credential use, persistence, or destructive behavior was found.

Install only if you want LLCClass-branded Wyoming LLC formation information. Verify fees, deadlines, BOI, tax, and filing requirements with official Wyoming, IRS, and FinCEN sources, and consult a qualified legal or tax professional before acting on the guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Low
Confidence
99% confidence
Finding
The README contains unresolved Git merge-conflict markers and two contradictory top-level descriptions, which indicates the skill was published in an inconsistent and potentially unreviewed state. In an agent skill context, this can mislead operators about what content is authoritative and may cause downstream ingestion, packaging, or trust decisions to rely on corrupted documentation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill presents legal, tax, compliance, and business-formation guidance in an authoritative tone without clearly stating that it is informational only and not legal, tax, or professional advice. Because users may rely on agent-delivered outputs for real-world filing, compliance, and structuring decisions, the absence of a disclaimer increases the risk of harmful overreliance, regulatory mistakes, and financial or legal consequences.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.