Cancel Task

Security checks across malware telemetry and agentic risk

Overview

This skill helps cancel a user’s own OpenAnt task and recover escrowed funds, with the irreversible action disclosed and gated on explicit confirmation.

Install this only if you use OpenAnt and want agent help cancelling your own tasks. Before confirming, verify the task ID, title, status, reward amount, assignee status, and refund details, because the skill describes cancellation as irreversible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description includes broad natural-language triggers such as 'I changed my mind', 'close this task', and 'never mind on this one', plus an instruction to 'make sure to use this skill' even when the user does not say cancel explicitly. This can cause over-selection of a destructive, irreversible skill based on ambiguous user intent, increasing the chance of unintended task cancellation and refund actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal