Token Launcher - Tator Launch Pad

Security checks across malware telemetry and agentic risk

Overview

This is a transparent documentation-only token-launching skill, but it can guide real blockchain transactions and Direct Mode requires careful wallet-key handling.

Use Easy Mode if you want the lowest key-handling risk, but remember it sends your public wallet address, prompt, and provider name to the Tator API and returns transactions you should inspect before signing. Use Direct Mode only with a dedicated low-balance wallet, secrets-manager storage, pinned dependencies, verified contract addresses, and explicit human approval before every transaction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger list is unusually broad and includes generic phrases like 'token idea', 'launch a coin', and 'is this a good token', which can cause the skill to activate in contexts where a user did not clearly intend high-risk financial or blockchain actions. In an agent environment, unintended invocation can escalate from harmless advice into workflows that discuss deployment, fee collection, or external API use, increasing the chance of unsafe or unauthorized token-launch assistance.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal