Back to skill

Security audit

Cournot

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed Cournot probability-query integration with explicit payment confirmation and no hidden credential handling.

Before installing, understand that Cournot sends your event query to an external service and may require a real on-chain wallet payment after the free allowance is exhausted. The artifacts require explicit confirmation before wallet setup or payment execution, but users should still review payment route, amount, network, and recipient carefully before confirming.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/cournot-client.mjs:290