Back to skill

Security audit

iaiops-plcnext

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a disclosed PLC monitoring package, but its read-only framing conflicts with listed export and publish tools that could move sensitive plant data.

Install only if you are comfortable with agents using this skill around PLCnext operational data. Treat it as read-only with respect to PLC writes, not necessarily read-only with respect to data leaving the environment; require explicit destination approval and local site policy for export, publish, historian push, UNS publish, and compliance evidence bundles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest and description repeatedly state this edition is read-only, but the documented tool surface includes capabilities such as historian_push, export_data, stream_publish, uns_publish, stream_publish_event, and compliance_report/evidence export. This mismatch can mislead operators, policy engines, or downstream agents into granting the skill elevated trust or fewer safeguards, enabling unintended outbound data movement despite a read-only safety claim.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The workflow section says the edition is entirely read-only, yet the tool list exposes multiple egress actions that can transmit or package operational data externally. In an OT/ICS context, even if no PLC state is modified, publishing historian data, events, or compliance bundles can leak sensitive plant telemetry, incident evidence, or asset information to unauthorized destinations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.