Back to skill

Security audit

iaiops-water

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly coherent for water-treatment diagnostics, but it says the water edition is read-only while listing export, publish, and historian-push capabilities that could move operational data.

Review this skill carefully before installing in a plant or utility environment. It appears aimed at diagnostics, but the published instructions should be corrected or constrained so that any export, publish, or historian-push actions are either unavailable in the water profile or clearly gated by explicit operator approval and audit logging.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill repeatedly claims the water edition is read-only, but the documented tool inventory includes capabilities such as historian_push, export_data, stream_publish, uns_publish, and stream_publish_event. In an industrial water-treatment context, this mismatch can cause operators or higher-level agents to trust the skill as non-mutating when it may transmit, export, or persist operational data, increasing the risk of unintended data exfiltration or unauthorized state-changing workflows through adjacent systems.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The workflow section states the edition surface is fully read-only, yet the broader capability list documents operations that can push, publish, or export data. This contradiction is dangerous because agents and users may rely on the workflow guidance as a safety boundary, while the available tools could still move sensitive plant telemetry or trigger downstream side effects in connected historian, stream, or UNS environments.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.