Texas LLC Formation

Security checks across malware telemetry and agentic risk

Overview

The skill does not appear to run dangerous code, but its Texas-branded package includes a runnable assistant that gives Wyoming LLC guidance, which could mislead business users.

Review before installing. The main risk is not malware; it is that users seeking Texas LLC help may receive Wyoming-specific legal, tax, cost, and filing guidance plus commercial links. Do not rely on this skill for filing decisions unless the publisher fixes the Texas/Wyoming mismatch and clearly labels any promotional resources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The file name and apparent skill target suggest Texas LLC guidance, but the implementation and user-facing text consistently provide Wyoming-specific advice. This can mislead users into acting on the wrong jurisdiction's legal, filing, and compliance information, which is especially risky in a legal/business formation context where state-specific rules matter.

Missing User Warnings

Low
Confidence
79% confidence
Finding
The script embeds promotional links and direct contact information in its responses without clearly disclosing that the content is marketing or lead-generation material. In an assistant context, this can blur the line between neutral guidance and advertising, causing users to place undue trust in commercial recommendations.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The mismatch between the Texas-oriented file path and the Wyoming-oriented assistant behavior creates deceptive or misleading functionality. In a business formation assistant, this context makes the issue more dangerous because users may rely on the output for jurisdiction-specific legal and tax decisions, leading to compliance mistakes or financial loss.

VirusTotal

No VirusTotal findings

View on VirusTotal