Back to skill

Security audit

Agnic Fund Wallet

Security checks across malware telemetry and agentic risk

Overview

This appears to be a wallet-funding guidance skill with no evidence of hidden execution, credential theft, persistence, or destructive behavior.

Install only if you want agent help with funding an Agnic wallet. Because the trigger phrases are broad, confirm the skill is being applied to the Agnic wallet before following any deposit or top-up instructions, and independently verify network, token, and destination address before sending funds.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill advertises several broad trigger phrases such as 'add funds', 'deposit', 'top up', and 'need more balance', which can overlap with common user language outside the narrow wallet-funding context. This can cause unintended invocation of the skill, leading the agent to steer users into wallet-specific funding instructions when they may have meant a different account, product, or balance context.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.