AgentAPI Hub

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is a coherent API directory, but it also tells agents how to make USDC payments without clear approval or spending controls.

Install only if you are comfortable with an agent reading this as permission to use paid x402 endpoints. Do not give the agent broad wallet access; require per-payment approval, verify the price and recipient, and use a low-balance or spending-limited wallet for any paid calls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal