Acp Job Submitter

Security checks across malware telemetry and agentic risk

Overview

This skill openly brokers paid jobs to third-party ACP agents, but it lacks clear safeguards for crypto, trading, payment, and data-sharing risks.

Install only if you intentionally want an agent to submit paid jobs to third-party ACP agents. Before each use, confirm the destination agent, service, requirements payload, exact cost, payer wallet, and markup recipient. Do not send private keys, credentials, personal data, or sensitive trading strategy, and require explicit approval before any swap, perpetual trade, or other asset-affecting job.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill is explicitly designed to submit jobs to third-party ACP agents, which means user prompts and requirement payloads may be transmitted off-system. Omitting a clear disclosure can cause users to unknowingly send sensitive financial, wallet, or strategy data to external services with different trust boundaries and privacy practices.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The automation examples promote trading and whale-tracking workflows that can influence financial decisions, yet they provide no warning that external agent outputs may be inaccurate, manipulated, delayed, or unsuitable for autonomous execution. In a crypto context, this is more dangerous because users may act on unverified signals or chain together automated actions affecting funds or market positions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal