Tezos Skill

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Tezos development guide, but users should treat its blockchain deployment examples as real financial actions.

Safe to install as a Tezos development reference. Before approving any octez-client command, confirm the network, account, contract address, transfer amount, burn cap, and whether it is a dry run; do not approve mainnet deployment unless you intend to spend real XTZ and create an irreversible on-chain contract.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill provides a mainnet origination command that will create a real Tezos contract and consume real XTZ, but the surrounding guidance does not make the irreversible financial consequences explicit at the point of action. In an agent-skill context, users may copy or trigger commands with reduced scrutiny, increasing the chance of unintended production deployment and monetary loss.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal