Back to plugin

Security audit

Agent Wallet

Security checks across malware telemetry and agentic risk

Overview

The skill is purpose-aligned for wallet operations, but it needs Review because it can move real funds and enable broad autonomous wallet permissions.

Install only if you intend to give the agent wallet authority over real mainnet funds. Review the external AgentLayer wallet runtime before use, keep autonomous approval disabled unless you deliberately need it, revoke it after use, and preview x402 payments manually before letting the agent pay arbitrary endpoints.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

61/61 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/index.js:430
Evidence
const stdout = execFileSync(

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.ts:430
Evidence
const stdout = execFileSync(