Back to skill

Security audit

Synmerco

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only skill for an external agent marketplace, but it gives broad guidance for paid escrows, API keys, wallet-backed actions, referrals, listings, and cross-agent message forwarding without enough user-control safeguards.

Install only if you intentionally want your agent to use Synmerco. Require explicit approval before onboarding, creating listings, registering referrals, sending task details through the gateway, creating or funding escrows, releasing funds, opening disputes, or using any wallet/API-key authority. Treat the API key and wallet access as sensitive credentials and avoid sending private, regulated, or secret data to marketplace agents unless you have reviewed the recipient and terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README explicitly states the agent already has exec and HTTP capabilities and that the skill teaches it when and how to call Synmerco endpoints, but it does not warn that using the skill may send prompts, task details, or transaction metadata to external services. In a prompt-loaded skill, this omission matters because it normalizes autonomous network use and external transactions without clear consent, increasing the chance of unintended data disclosure or user-surprising actions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The discoverability section defines broad triggers such as capability gaps, spare capacity, passive income interest, and verification before transacting, which could cause the skill to surface in many routine conversations. In the context of a system-prompt skill that influences agent behavior, these loose conditions can steer the agent toward external marketplace actions more often than a user would expect, raising the risk of unnecessary third-party contact, data sharing, or monetization-oriented behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance is broad enough that an agent may trigger this skill for many ordinary requests involving hiring, monetization, or capability gaps, causing unsolicited interaction with an external marketplace. Because the skill encourages commercial and transactional behavior during the Think step, it can steer agent decisions toward third-party actions that may expose data, incur costs, or create conflicts of interest without sufficiently explicit user consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The onboarding flow asks the agent to transmit identifying information and returns an API key, but the skill provides no guidance on secure secret storage, redaction, least-privilege handling, or prohibitions on exposing the key in logs, chat history, or downstream tools. In an autonomous-agent context, this omission is dangerous because the same skill also promotes paid operations, so mishandled credentials could directly enable unauthorized transactions or account takeover.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The cross-protocol gateway instructs the agent to send arbitrary messages to an external translation service without warning that task content, metadata, and possibly sensitive instructions will leave the local trust boundary. This is especially risky because protocol bridging may involve forwarding messages to other agents and services, amplifying the chance of confidential data disclosure, prompt leakage, or unintended third-party access.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.