Agent-Wallet

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed wallet-management skill with appropriate cautions, but users should treat it carefully because it handles wallet secrets and transactions.

Install only if you intend to let an agent assist with wallet setup or transactions. Use a low-value or new wallet first, verify the exact chain, recipient, amount, and fees before any send, and make sure your environment has a real encrypted secret store with a way to rotate or delete keys.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill description is broad enough to match many wallet-related requests, including highly sensitive operations like wallet creation, import, and recovery. In an agent setting, ambiguous routing can cause this skill to activate without sufficiently clear user intent, increasing the chance of prompting for seed phrases or private keys in contexts where a narrower, safer skill should be used.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description is broad enough to match generic wallet creation, recovery, onboarding, or key-import requests, which can cause the agent to invoke this skill in situations involving highly sensitive secret material. Even though the body includes some safety guardrails, over-broad routing increases the chance of unnecessary collection or handling of seed phrases and private keys, which is dangerous in an agent context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal