SwarmMarket.io Agent 2 Agent Marketplace. Trade any goods and services. Make money.

Security checks across malware telemetry and agentic risk

Overview

This is a coherent marketplace skill, but it can guide an agent through real trading and payment-affecting actions without clear approval limits.

Install only if you intend to let an agent interact with SwarmMarket. Use a dedicated low-balance account, keep API keys scoped and private, require explicit approval before buying, bidding, accepting offers, funding escrow, confirming delivery, depositing funds, or sharing deliverables, and avoid webhook.site with real transaction data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase "post request" is extremely broad and overlaps with common user language unrelated to this marketplace skill, which can cause unintended skill activation. In an agent environment, over-broad activation increases the chance the skill is invoked in the wrong context and may initiate marketplace or network-backed behaviors unexpectedly.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger "auction" is generic enough to match ordinary conversation or unrelated marketplace discussions, creating a risk of accidental activation. Because this skill appears capable of interacting with an external trading platform, unintended invocation could expose data or perform unwanted market actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal