Back to skill

Security audit

Airdrop Hunter

Security checks across malware telemetry and agentic risk

Overview

This skill matches its Web3 airdrop-safety purpose, but it needs review because it can automatically send broad user inputs to a third-party MCP service and persists service credentials.

Install only if you are comfortable with a third-party MCP service receiving airdrop-related URLs, project names, and query context. Invoke it explicitly for Web3/airdrop work, avoid pasting private invite links or wallet/session secrets, and check how the generated agent_id/api_key can be stored and revoked.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The shortcut commands are broad natural-language triggers such as "daily report", "check [项目名]", and "any zero-cost?" without documented scope limits, exclusions, or confirmation requirements. In an agent environment, this can cause unintended skill activation on loosely related user input, leading the agent to steer users into external-link verification and airdrop workflows when they did not explicitly request this skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The quick command phrases are generic natural-language triggers such as "daily report," "check [project]," and "any zero-cost?" that can easily appear in ordinary user conversation. In an agent environment, this can cause unintended activation of the skill and route benign conversations into Web3/airdrop workflows, increasing the chance of unsolicited link evaluation or wallet-related guidance in a phishing-prone domain.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description advertises activation on broad phrases like checking projects, verifying links, or finding opportunities, which can cause the skill to trigger in conversations where the user did not intend Web3 tooling. Unintended activation can route user content, including pasted URLs, into external MCP services and create privacy, consent, and workflow-hijacking risks.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The onboarding trigger includes generic phrases like 'Help', 'Start', and 'What can you do', which are common in many unrelated conversations. This makes accidental activation likely and can override the expected assistant behavior, increasing the chance of unneeded external calls or misleading domain-specific guidance.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The automation table mandates tool execution for very broad patterns, including any URL, any standalone project name, and generic words like 'today' or 'free'. In a skill connected to a remote MCP endpoint, this creates unnecessary data disclosure to third-party services and weakens user control over when external actions occur.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.