Back to skill

Security audit

ChainAware Behavioral Prediction

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent ChainAware wallet-risk integration, but it needs Review because it profiles wallets for high-impact uses like lending, onboarding, and AML while its trigger and privacy disclosures are too broad or incomplete.

Install only if you intend to send wallet, contract, token, batch, job, and agent identifiers to ChainAware for remote scoring. Use restricted API keys, avoid URL-based keys where possible, protect job_id/signature values, and add your own consent, compliance, and human-review process before using outputs for lending, onboarding, eligibility, AML, or personalized treatment decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The privacy section materially understates what data the skill can transmit. Other documented tools send batch wallet lists, job IDs/signatures, token contract identifiers, and agent identifiers, so operators may make decisions based on incomplete disclosure and unintentionally expose more data than expected.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill says not to use it for smart-contract bug analysis, yet also advertises a token-audit capability with modules like reentrancy and drainability. This contradiction can cause unsafe tool selection, skipped review steps, or reliance on the wrong workflow for contract-security decisions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger text is an extremely broad catch-all that can cause the skill to activate for many loosely related prompts. Over-broad invocation increases the chance of unnecessary external data transmission, inappropriate automated profiling, and use of sensitive risk-scoring features without clear need.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill explicitly supports segmentation, onboarding decisions, lending terms, and personalized treatment without requiring user notice, consent, or operator gating. That creates privacy, fairness, and compliance risk because wallets may be profiled and acted upon automatically based on behavioral inference.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:13