Back to skill

Security audit

iaiops-warehouse

Security checks across malware telemetry and agentic risk

Overview

The skill is relevant to warehouse industrial operations, but it advertises a read-only tool surface while documenting high-impact write actions against production OT systems.

Review this skill before installing in any real warehouse or industrial environment. It may be useful for diagnostics and analytics, but operators should treat it as having potential production write authority and should require explicit approval gates, dry-run defaults, and clear separation of read-only versus write-capable use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest explicitly says the warehouse edition's tool surface is read-only, but the body documents write-capable tools such as `eip_write_tag`, `profinet_dcp_set`, `mqtt_publish`, `stream_publish`, and `uns_publish`. This mismatch can cause an agent or operator to trust the skill as non-invasive and then invoke state-changing operations against production OT systems, which is especially dangerous in warehouse automation where PLC and network-configuration changes can disrupt conveyors, sorters, or AGV operations.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The documentation repeatedly frames the edition as 'read-only' or 'read-first' while later sections describe production write capabilities and MOC workflows. Even if approvals and dry-run defaults exist, the contradictory safety posture can mislead downstream automation, prompt selection, or human reviewers into underestimating the risk of executing commands that change PLC tags or Profinet station settings.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.