Back to skill

Security audit

NEXUS Research

Security checks across malware telemetry and agentic risk

Overview

This is a paid remote research skill that is mostly disclosed, but its broad automatic invocation and payment authority need review before use.

Install only if you trust NEXUS with your research prompts and are comfortable with possible per-request charges. Use the sandbox first, avoid sending secrets or regulated/private data, and configure any real payment proof only in an agent setup that requires explicit approval and spending limits for each paid call.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The README presents the package as an automatically invoked local skill, but the documented behavior is a paid remote API that requires outbound network requests and payment credentials. This mismatch can cause users or agents to invoke it without realizing prompts and possibly sensitive data will be sent off-host to a third party and may trigger payment flows.

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
The documented payment-protocol, blockchain, and multi-network integration materially expands the skill's operational scope beyond 'deep research' into financial transaction handling. That broader capability increases risk because an agent or user may unknowingly engage payment systems, escrow flows, or credential handling that were not clearly scoped in the skill's stated purpose.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Saying the skill is 'automatically invoked ... when a matching task is detected' is too vague for a capability that sends data to an external paid service. Ambiguous trigger conditions can lead to unintended activation, external data disclosure, and unexpected charges, especially in autonomous-agent environments.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README shows research requests being posted to an external host but does not prominently warn that user queries are transmitted to a third-party service. In a research assistant context, prompts may contain sensitive business, personal, or proprietary information, making silent exfiltration to a remote endpoint a significant privacy and security risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.