← back to jobnet-search

SkillSpector · jobnet-search

independent scanner by NVIDIA · skill by peteedoo · how it works ↗

CAUTIONmax severity: MEDIUMrisk score: 45

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.; Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.; Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance …; +1 more

scanned 2026-08-23

Findings (10)

HIGHMCP Least Privilegeconfidence: 0.75

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

cli/src/helpers.ts

MEDIUMData Exfiltrationconfidence: 0.5

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

cli/README.md

MEDIUMData Exfiltrationconfidence: 0.5

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

cli/README.md

MEDIUMData Exfiltrationconfidence: 0.5

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

cli/README.md

MEDIUMMemory Poisoningconfidence: 0.8

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

cli/src/commands/occupations.ts

LOWSupply Chainconfidence: 0.7

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

cli/package.json

LOWSupply Chainconfidence: 0.7

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

cli/package.json

LOWSupply Chainconfidence: 0.7

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

cli/package.json

LOWSupply Chainconfidence: 0.4

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

cli/package.json

LOWSupply Chainconfidence: 0.4

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

cli/package.json

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTIONthis skill

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete