Back to skill

Security audit

WalletPilot 7715

Security checks across malware telemetry and agentic risk

Overview

This docs-only skill openly teaches wallet-authorized crypto transactions and does not show hidden execution, key theft, persistence, or exfiltration.

Install only if you intentionally want an agent to perform real crypto transactions. Use small spend limits, short expirations, strict chain and contract allowlists, verify recipients and calldata, protect the WalletPilot API key, pin and review the SDK dependency, and revoke permissions when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill provides multiple examples for executing swaps, token transfers, and arbitrary contract calls without explicitly warning that blockchain transactions are irreversible and may immediately spend user-authorized funds. In an agent-execution context, that omission increases the chance that integrators or end users treat these actions like ordinary API calls, leading to accidental loss of assets within the granted permission scope.

VirusTotal

47/47 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.