Back to skill

Security audit

builder-data

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only helper for read-only Talent Protocol and GitHub lookups, with identity-linking privacy considerations but no hidden code, persistence, or destructive behavior.

Install only if you are comfortable with an agent querying Talent Protocol and optionally GitHub for identity-linked builder data such as wallets, social handles, locations, credentials, rankings, and public repository activity. Use least-privilege API credentials, avoid broad or covert people searches, and only run wallet-to-identity or enrichment lookups for a legitimate user-directed purpose.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is framed with broad, high-level invocation language such as finding verified developers, mapping social accounts to wallets, and checking credentials, but it does not define clear trigger constraints, user-consent expectations, or prohibited use cases. That increases the chance an agent will invoke it for identity correlation or profiling tasks beyond a user's reasonable expectations, especially when combined with external enrichment and ranking features.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill advertises identity resolution across Twitter, Farcaster, GitHub, and wallet addresses and retrieval of profile, credential, and location-related data, but it does not present a user-facing privacy warning or consent guidance. This is dangerous because it enables cross-platform deanonymization and enrichment of personal data from external sources without making privacy implications explicit to the requesting workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal