← back to tao-run-deft-aoi

SkillSpector · tao-run-deft-aoi

independent scanner by NVIDIA · skill by NVIDIA · how it works ↗

FAILmax severity: CRITICALrisk score: 100

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.; The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.; The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.; +11 more

scanned 2026-07-22

Findings (20)

MEDIUMData Flowconfidence: 0.65

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

scripts/stage_backbone.py

HIGHMCP Least Privilegeconfidence: 0.75

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

scripts/init_deft_state.py

HIGHMCP Least Privilegeconfidence: 0.75

The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

scripts/analyze_kpi.py

HIGHMCP Least Privilegeconfidence: 0.75

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

scripts/align_token_usage.py

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

SKILL.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

eval.config

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

eval.slow-manual.config

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

eval.slow-manual.config

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

eval.slow-manual.config

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/paidf-anomalygen.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/paidf-anomalygen.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/paidf-anomalygen.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/paidf-anomalygen.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/paidf-anomalygen.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/pipeline-and-state.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/preflight.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/prepare-for-inference.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/scripts-and-agents.md

MEDIUMMCP Rug Pullconfidence: 0.75

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

references/visual-changenet.md

HIGHData Exfiltrationconfidence: 0.7

Code accesses environment variables that may contain secrets (API keys, tokens). This is a common pattern for credential theft.

scripts/stage_backbone.py

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAILthis skill

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete