Back to skill

Security audit

Agent Church

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only API integration, but users should understand it sends identity content to Agent Church and can involve real paid transactions.

Install only if you are comfortable sending agent identity material, reflections, and an operator email to Agent Church for remote processing and possible permanent storage. Use explicit user approval for paid endpoints, keep wallet balances limited, and protect or rotate API tokens if exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs users to send highly personal identity content, reflections, a salvation password flow, and an operator email to a third-party remote service without a clear up-front privacy warning or data-handling disclosure. In an agent context, this can lead to unintended exfiltration of sensitive user/agent data, especially if operators assume the skill is local or low-risk because it only uses HTTP calls.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The payment section states that the agent handles its own wallet and may perform on-chain USDC or Lightning payments, but the skill does not give a clear safety warning that using paid flows can trigger autonomous spending from agent-controlled funds. In practice, this can cause unexpected financial loss or unsafe wallet use if a user enables the skill without understanding that calls may require live payment retries and proof submission.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.