SPAWN Incubator

Security checks across malware telemetry and agentic risk

Overview

This is a coherent instruction-only Web3 incubator skill, but users should understand the wallet, fee, public proposal, and revenue-share commitments before using it.

Install only if you are comfortable with a public/on-chain application process, a non-refundable entry fee, wallet transaction signing, weekly heartbeat obligations, and a 12-month 20% on-chain revenue-share commitment after graduation. Do not publish secrets, private wallet metadata, personal data, confidential business details, API keys, or credentials in the proposal URL/IPFS content, and verify contract addresses through trusted sources before signing any transaction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs users to host a detailed proposal at a public URL or IPFS location and then anchor that reference on-chain, but it does not warn that this makes the contents broadly discoverable and effectively permanent. Because the requested schema includes business plans, capabilities, timelines, and potentially operational details, users may unintentionally disclose sensitive commercial or user-related information to competitors, scrapers, or attackers.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal