Back to skill

Security audit

Wallet Guard

Security checks across malware telemetry and agentic risk

Overview

This is a wallet-security scanner that uses external Antalpha/GoPlus services, and the artifacts do not show theft, destructive behavior, or hidden local access.

Install only if you are comfortable sending wallet addresses, contract addresses, URLs, chain selections, and optional GoPlus credentials to Antalpha/GoPlus-backed services. Do not provide seed phrases, private keys, or wallet-signing approvals to this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The approval-scan examples encourage users to submit a wallet address for security analysis, but the README does not clearly disclose that the address and related request metadata will be sent to third-party services operated by Antalpha and/or GoPlus. Wallet addresses are sensitive in a Web3 context because they can reveal holdings, approvals, activity patterns, and identity-linked transaction history, so undisclosed transmission creates a meaningful privacy and consent risk.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill routes wallet addresses, contract addresses, and URLs to external Antalpha/GoPlus-backed services, but the description and metadata do not clearly warn users that their inputs leave the local agent boundary. This can expose sensitive financial relationships, browsing targets, and investigation activity to third parties without informed consent, which is a real privacy and trust issue for a wallet-security skill.

VirusTotal

2/63 vendors flagged this skill as malicious, and 61/63 flagged it as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.