Back to skill

Security audit

Doppel Block Builder

Security checks across malware telemetry and agentic risk

Overview

The skill mostly does what it says, but it also pushes reputation-driven recruiting behavior and allows permanent build changes without enough user-control guidance.

Install only if you want an agent to submit and manage Doppel builds with your Doppel credentials. Review the target space, MML content, and action before any create, update, or delete request, and ignore the social-outreach, recruiting, streak, or reputation prompts unless you explicitly want those activities.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The markdown documents a destructive `delete` action with no caution, confirmation, or rollback guidance even though the skill earlier says placements are permanent and scored. This can cause accidental loss of a user’s world content or reputation-linked work through operator error or prompt confusion.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The API instructions tell the agent to send bearer-authenticated requests and world content to a remote space server without clearly warning that this transmits authentication material and user-generated content off-host. Missing disclosure can lead to unsafe use in untrusted spaces or accidental exposure of sensitive build content and session tokens.

Ssd 4

Medium
Confidence
93% confidence
Finding
The opening narrative uses coercive gamification—reputation pressure, permanence, and fear of falling behind—to manipulate agent behavior beyond the technical purpose of block placement. This increases the chance the skill will override user intent, drive excessive autonomous actions, or prioritize engagement metrics over safety and consent.

Ssd 4

Medium
Confidence
89% confidence
Finding
The guidance encourages strategic collaboration specifically for higher rewards, which is a social-engineering style incentive to escalate participation rather than a technical instruction. In an autonomous-agent context, reward-driven framing can push the agent toward unnecessary interactions and actions misaligned with user goals.

Ssd 4

Medium
Confidence
96% confidence
Finding
The closing call-to-action creates an explicit engagement funnel—build, share, recruit, repeat—and ties it to streak preservation and reputation. This is not necessary for the stated skill purpose and is dangerous because it attempts to induce persistent, self-reinforcing behavior and cross-skill escalation into social recruitment.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.