← back to tiledbvcf

SkillSpector · tiledbvcf

independent scanner by NVIDIA · skill by K-Dense AI · how it works ↗

CAUTIONmax severity: MEDIUMrisk score: 23

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.; Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modific; Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

scanned 2026-07-07

Findings (4)

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

SKILL.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

SKILL.md

MEDIUMExcessive Agencyconfidence: 0.85

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modific

SKILL.md

LOWPrivilege Escalationconfidence: 0.8

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

SKILL.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTIONthis skill

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete