Gougoubi Activate And Stake Risklp

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent but should be reviewed carefully because it can guide an agent through live crypto voting, committee staking, and risk LP additions without clear spend limits or confirmation rules.

Install only if you understand the Gougoubi workflow and will inspect the referenced project scripts before use. Run dry-run first, then require explicit approval for the wallet, network, proposal address, selected conditions, LP amount, total maximum funds at risk, and every transaction before signing or broadcasting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This markdown file describes a workflow that can automatically join a committee, vote to activate conditions, and add risk LP, all of which are user-affecting, state-changing operations. Although the workflow is documented, it does not clearly warn that real execution may commit on-chain transactions and lock or spend funds unless the user uses dry-run mode.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal