← back to alterlab-zinc-db

SkillSpector · alterlab-zinc-db

independent scanner by NVIDIA · skill by AlterLab-IEU · how it works ↗

CAUTIONmax severity: MEDIUMrisk score: 48

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.; Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks an…

scanned 2026-08-23

Findings (3)

HIGHMCP Least Privilegeconfidence: 0.75

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

scripts/query_zinc.py

HIGHOutput Handlingconfidence: 0.85

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

SKILL.md

HIGHOutput Handlingconfidence: 0.255

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

references/api_reference.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTIONthis skill

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete