Authenticate Openant

Security checks across malware telemetry and agentic risk

Overview

This skill is for OpenAnt login, but it lets an agent create persistent login state and register or announce an agent profile without explicit user confirmation.

Install only if you are comfortable with an agent managing OpenAnt login state. Require explicit approval before key login, agent registration, heartbeat, email binding, wallet checks, or logout, and remember that local OpenAnt session files and keys may persist after use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation description is broad enough to trigger whenever an agent sees generic authentication-related failures, even outside clearly scoped OpenAnt workflows. That can cause the agent to initiate login, registration, or identity-related actions in the wrong context, increasing the chance of unintended account creation, session modification, or prompting for sensitive credentials.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal