Aavegotchi Renderer Bypass

Security checks across malware telemetry and agentic risk

Overview

This skill appears to do what it says: render public Aavegotchi assets through public APIs and save the requested output files locally.

Install only if you are comfortable running a local Node script that contacts Goldsky and Aavegotchi and writes JSON/PNG artifacts. Use public token IDs, avoid accepting --out-dir values from untrusted input, and choose a dedicated output directory instead of a shared or sensitive path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs saving raw API JSON and downloaded image artifacts to disk, but provides no warning, consent step, retention guidance, or constraints on where data is written. Even if the content is not highly sensitive, silent local file writes can create privacy, persistence, and disk-usage risks in agent environments, especially when output paths are user-controlled or shared.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal