Back to skill

Security audit

iaiops-renewables

Security checks across malware telemetry and agentic risk

Overview

The skill mostly fits a renewables monitoring purpose, but it repeatedly calls itself read-only while documenting publish, push, and export tools that can change or leak operational data.

Review this skill before installing in any real plant, SCADA, MQTT, UNS, or historian environment. If you use it, restrict the MCP/tool policy to read-only methods unless you explicitly need publishing or exports, and require destination allowlists and user confirmation for any push, publish, or export action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The skill repeatedly claims the renewables edition is read-only, yet the documented tool surface includes clearly write-capable operations such as mqtt_publish, stream_publish, uns_publish, historian_push, and export_data. This mismatch can mislead an agent or operator into invoking state-changing or data-exfiltrating actions under the false assumption that the skill is safe for passive observation only.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
Within the tool inventory, the documentation says the edition is read-only but then exposes MQTT and cross-protocol tools that can publish, push, or export data. In an industrial/OT context, even a 'publish-only' capability can alter downstream systems, trigger automations, poison telemetry, or leak sensitive operational data, so the contradiction materially increases misuse risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.