ETHSkills

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Ethereum development documentation helper with normal developer-tool supply-chain caution but no evidence of hidden or harmful behavior.

Install this if you want Ethereum development documentation surfaced during coding tasks. Keep it scoped to development work, and treat any npm/npx scaffolding command as code execution: run it only when you intentionally want to create a project and are comfortable with the package source.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill's trigger conditions are extremely broad, covering nearly any Ethereum, EVM, wallet, token, gas, smart contract, or general web3 development request. This can cause the agent to over-invoke an external knowledge source, increasing the chance of inappropriate routing, overreliance on remote content, and unnecessary exposure to untrusted or changing instructions from fetched documentation.

VirusTotal

50/50 vendors flagged this skill as clean.

View on VirusTotal