Quick Intel Token Security Scanner

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a transparent token-contract scanning helper, but users should be aware that scans may contact Quick Intel and may involve x402 payment.

Install only if you are comfortable sending token or contract identifiers to Quick Intel and using x402 payments. Use a dedicated low-balance wallet or managed wallet service for any signing flow, keep main wallet private keys out of the skill, and confirm each paid scan before it runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad, common phrases such as 'is this token safe', 'audit contract', and 'safe to buy', which can cause the skill to activate in situations where the user did not clearly intend to initiate a paid external scan. In this skill, unintended invocation is more concerning because each scan can trigger an x402 payment and send token/query data to third parties.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal