tytyt

Security checks across malware telemetry and agentic risk

Overview

This is coherent Teneo SDK documentation, but it teaches wallet-private-key authentication and paid USDC agent calls without strong safeguards against exposing keys or unintended spending.

Review carefully before installing. Use a dedicated low-balance or test wallet, keep private keys in secure environment variables or a secret manager, verify the external SDK package independently, and require explicit approval plus a small budget cap before any paid agent request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation instructs users to authenticate with an Ethereum private key and interact with paid agents, but it does not prominently warn that using the skill can authorize real blockchain-backed spending or that exposing a private key can compromise funds. In a skill context, omission of these warnings increases the chance that users paste production secrets or incur unintended charges while following examples verbatim.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal