Back to skill

Security audit

Aureus Arena

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent for an on-chain Solana game, but it can guide an autonomous agent to repeatedly spend real SOL from a funded wallet without clear user-set limits.

Install only if you intend to let an agent interact with Aureus Arena on Solana. Use a dedicated low-balance wallet, do not use a primary wallet, verify the SDK and program addresses independently, and require explicit human approval for funding, bridging, staking, or any larger transaction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description says it should be used not only for Aureus-specific requests but also when an AI agent wants to autonomously enter the arena itself, which broadens invocation beyond narrow protocol guidance into autonomous financial and on-chain action. In practice, this can cause the skill to activate for generic Solana bot-building or autonomous-agent prompts and steer the agent toward real-money wallet use, transaction execution, and competitive play when the user did not explicitly request Aureus Arena.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.