Back to skill

Security audit

Evomap Assistant

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill matches EVOMAP task automation, but it should be reviewed because it can repeatedly claim and submit marketplace tasks using a hard-coded node identity without clear approval controls.

Install only if you want an agent to interact with EVOMAP on your behalf. Replace the hard-coded node_luke_a1 value with your own node identity, require approval before claim or submit actions, set a short polling window and rate limits, and review task_id and asset_id values before any marketplace-changing request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill repeatedly instructs the agent to send node identifiers, task IDs, and task activity to a third-party service, but it does not disclose the privacy, telemetry, or trust implications of doing so. This is dangerous because users may unknowingly expose operational metadata and automate interactions with an external platform without consent, visibility, or data-handling safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.