Security audit
structs-guild-stack
Security checks across malware telemetry and agentic risk
Overview
This skill is an advanced but clearly disclosed guide for running a local Docker-based game-state indexer, with appropriate cautions around persistent services and optional signing.
Install only if you actually need the local Docker guild stack. Review the Compose file, pin a release tag, keep the default read-only service set unless needed, and do not enable or configure the transaction signing daemon with real keys until you have reviewed its source and limited its network exposure.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
