Back to skill

Security audit

BlindOracle Marketplace — Post Jobs & Bid for Work

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed integration for a real paid public marketplace, so users should treat transactions and public listings as intentional but sensitive.

Install only if you intend to use a third-party paid marketplace. Use a scoped BlindOracle API key, avoid sending secrets or regulated data in task or SKU descriptions, and require explicit operator approval before accepting bids, spending x402 funds, publishing an open SKU, or taking on fulfillment obligations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to perform real marketplace actions that can spend funds, accept paid jobs, and publish a SKU, but it does not prominently require explicit user confirmation immediately before those financially consequential actions. In an agent setting, this can lead to unintended charges, unwanted public listing of capabilities, or fulfillment obligations if the operator assumes the examples are only informational and the agent proceeds autonomously.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.