Back to skill

Security audit

BagsWorld

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only BagsWorld integration whose wallet and token actions are disclosed, but users should treat them as financial and public actions.

Install only if you trust bagsworld.app and want BagsWorld integration. Use it only for explicit BagsWorld requests, avoid sharing personal details in public names or descriptions, treat wallet identifiers and onboarding secrets as sensitive, never give an agent or website your seed phrase or raw private key, and review every Solana transaction in a trusted wallet before signing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs agents to initiate token launches and fee-claim flows tied to wallets and unsigned Solana transactions, but it does not prominently warn about financial, irreversible, or on-chain consequences. In an agent setting, this can lead to users or downstream automation triggering economically meaningful actions without adequate consent, risk disclosure, or transaction review.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The API reference exposes multiple state-changing and financially sensitive actions such as token launches, fee claiming, onboarding, and world membership changes, but it does not provide explicit user-consent, transaction-review, or risk-warning guidance. In an agent skill context, this increases the chance that an autonomous agent could trigger economically meaningful actions or mishandle unsigned transactions without clear safeguards or informing the user.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.