Back to skill

Security audit

iaiops

Security checks across malware telemetry and agentic risk

Overview

The skill is a non-executable OT router with clearly disclosed safety gates, though users should notice its substation routing note before using it.

Before installing, confirm which edition package you actually need. For substations or energy protocols, follow the iaiops-energy redirect rather than trying to use this server profile. Treat any real OT writes as high-risk and only proceed with the documented dry-run, approval, and authorization controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest tells users to use this skill for electrical substations, but the body later says substation and energy protocols must use a different package and explicitly warns not to use this server for them. In an OT setting, this inconsistency can misroute users or automation to an unsupported toolchain, causing unsafe diagnostics assumptions, failed monitoring, or accidental operation against the wrong environment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.