Security audit
CARP
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed guide for using a local CARP interface, with sensitive actions like keys, ACL changes, and blockchain/escrow steps called out with user-approval safeguards.
Install only if you intend to operate a CARP/ADILOS agent interface. Keep IF_URL pointed at a trusted local or LAN endpoint, protect generated key files, and require explicit approval before any ACL, payment, blockchain, escrow, or external counterparty action.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
