Back to skill

Security audit

Julia Bounty Scout

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it encourages unattended bounty submissions and payment or wallet tracking without enough user-control safeguards.

Review carefully before installing. Use it only with explicit approval for every outbound proposal, PR, or platform interaction; avoid unattended background runs unless strict limits and logs are configured; and do not connect wallets or sensitive account credentials unless the skill clearly documents what it can read and write.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly encourages unattended background execution for revenue-generating actions, while earlier text states it can auto-generate proposals/PRs and track payments. That creates a real risk of the agent taking externally visible actions and handling financial/account data on the user's behalf without explicit consent, review gates, or disclosure, which can lead to spammy submissions, reputational damage, and unintended transactions or data exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.