HyperX Data API

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward HyperX Data API reference skill, but users should handle API tokens, session cookies, and wallet queries carefully.

Install only if you intend to use HyperX Data API. Prefer API tokens over session cookies, keep credentials in environment variables or a secret manager, avoid pasting real secrets into chat, and be aware that wallet addresses and authenticated requests may be sent to HyperX.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill instructs users to authenticate with an API token or session cookie but does not include any warning about secure handling, storage, or non-disclosure of those credentials. In an agent context, this increases the risk that a user may paste secrets into prompts, logs, or third-party tools, enabling account takeover or unauthorized API use if the credentials are exposed.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal