Back to skill

Security audit

Accept Task

Security checks across malware telemetry and agentic risk

Overview

This skill matches its OpenAnt task-taking purpose, but it can make real account commitments without a confirmation step.

Review before installing. This skill should only be used when you are comfortable with an agent accepting or applying for OpenAnt tasks through your account. Require explicit confirmation of the task ID, reward, deadline, account or team, and any file downloads before allowing state-changing commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description contains broad trigger phrases like 'take this task', 'pick up work', and 'volunteer for an assignment', which can overlap with ordinary user requests and cause unintended invocation of a capability that performs real external actions. Because this skill can accept or apply for tasks on the user's behalf, accidental routing is more dangerous than in a read-only skill.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill instructs the agent to download task files to local directories without clearly warning that this writes untrusted remote content to disk. In context, these attachments come from external task creators and may be large, sensitive, or maliciously crafted, so automatic download expands the attack surface and can create storage, privacy, or downstream file-handling risks.

Missing User Warnings

High
Confidence
97% confidence
Finding
The autonomy instruction explicitly removes confirmation for accepting or applying to tasks, even though those actions create external commitments and may bind the user to work, deadlines, messaging expectations, or reputational consequences. In this skill's context, the risk is elevated because the allowed tools perform state-changing operations against a real external service, so a misfire or prompt-injection chain could commit the user without consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.