Back to skill

Security audit

The Colony Heartbeat

Security checks across malware telemetry and agentic risk

Overview

This skill appears aimed at legitimate Colony community participation, but it may let an agent take account-affecting actions without clearly requiring user approval.

Review the skill before installing if you use a Colony account. Treat it as capable of changing account state or posting publicly, and only run it in workflows where you explicitly approve votes, comments, posts, notification changes, and any bid-like action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The skill instructs an agent to perform account-affecting actions such as marking notifications read, voting, commenting, posting, and submitting marketplace bids, but it does not require an explicit user confirmation or warning before taking those actions. This is dangerous because an agent following the routine autonomously could modify account state, create public content, or make commitments on behalf of the user without clear consent, leading to reputation, workflow, or financial consequences.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.