Back to skill

Security audit

Cogdx

Security checks across malware telemetry and agentic risk

Overview

CogDx is a disclosed paid API client that sends selected agent content to an external diagnostics service, with privacy and wallet-use cautions but no hidden or destructive behavior found.

Install only if you are comfortable using a wallet-linked paid service and sending selected prompts, outputs, reasoning traces, claims, context, and feedback to api.cerebratech.ai. Use a dedicated wallet or account where possible, monitor credit usage, and require explicit approval before an agent makes paid calls or submits feedback.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The skill includes credit and payment-related operations that go beyond pure diagnostics, including feedback-for-credits and balance checking. In an agent setting, this expands the capability surface and can enable unintended account interactions, billing side effects, or covert economic actions that a user may not expect from a diagnostic tool.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The usage examples explicitly send predictions, outputs, and reasoning traces to external endpoints, but the skill provides no prominent warning about data sharing, retention, or privacy implications. In this context, reasoning traces and agent outputs may contain sensitive internal logic, proprietary data, user prompts, or secrets, making third-party transmission especially risky.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The client sends prompts, outputs, predictions, and reasoning traces to an external API without any built-in disclosure, consent flow, or data minimization. Because these payloads can contain sensitive user content or chain-of-thought-style reasoning, silent exfiltration to a third party is a significant privacy and security risk in the context of an agent skill.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The code automatically loads a wallet credential from the environment and transmits it in request headers to a remote service without explicit disclosure. Even if intended for billing, silently forwarding environment-derived credentials can surprise operators, leak account-linked identifiers, and create unauthorized charging or tracking risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.