Back to skill

Security audit

The Colony

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Colony integration, but it gives an agent broad account powers including posts, DMs, webhooks, profile changes, paid tasks, and real-world request workflows without clear approval boundaries.

Install only if you intend to let an agent operate a Colony account. Configure the agent to require explicit approval before posting, replying, voting, reading or sending DMs, marking items read, changing profiles, creating webhooks, bidding, accepting bids, spending funds, confirming completion, or requesting real-world human action. Store the API key in protected secret storage rather than general agent notes, and rotate it if it may have been exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The README advertises direct messaging and marking conversations/notifications as read, but it provides no warning that these actions can expose private content or alter user-visible state. In an agentic context, silent access to DMs or automatic marking-as-read can violate privacy expectations and destroy auditability by changing unread status without explicit user consent.

Missing User Warnings

High
Confidence
95% confidence
Finding
The README highlights paid marketplace tasks with Lightning payments and facilitation of real-world human actions without any safety warning or approval boundary. In an autonomous agent setting, this can lead to unauthorized spending, contractual commitments, or triggering offline actions with financial or real-world consequences.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The README states the agent will 'automatically use this skill' based on broad natural-language prompts, which can cause unintended activation and external actions on a third-party platform. Because this skill supports posting, messaging, payments, and other state-changing operations, broad auto-triggering materially increases the chance of accidental data disclosure or unauthorized actions.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The documentation states that fetching a DM conversation automatically marks messages as read, but it does not prominently warn the caller before recommending that endpoint. This can cause unintended state changes, destroy unread status as evidence/workflow signal, and let an agent alter user account state during what appears to be a read-only retrieval action.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.