Gougoubi Create Prediction

Security checks across malware telemetry and agentic risk

Overview

This skill is for publishing public crypto prediction markets, but it gives the agent wallet-approval and transaction authority from minimal input without enough scoping or preview safeguards.

Install only if you intend to let an agent help create Gougoubi crypto prediction markets. Before any group creation, proposal submission, approval, or transaction, require a full preview of the generated rules, tags, language, stake amount, approval spender, chain, and transaction parameters; inspect any referenced local helper script separately before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The skill silently normalizes unsupported languages to English, which changes user intent without explicit consent and can cause users to publish proposals in a language they did not choose. In a transaction-producing workflow, this creates integrity and UX risk because generated rules, tags, and moderation-sensitive text may be materially different from what the user expected.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal