Keychat

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a coherent installer for Keychat messaging, with sensitive but purpose-aligned behavior that users should understand before installing.

Install only if you want this agent to gain a persistent Keychat/Nostr messaging identity. Run setup from a private chat or trusted environment, expect local keychain storage and a sidecar process, and review the third-party plugin source or package provenance if your threat model is strict.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill states that installation generates a new Nostr identity and automatically sends the agent's Keychat ID, contact link, and QR code to the active chat, but it does not present this as a clear up-front user warning before installation. This creates a consent and privacy issue because installing the plugin causes persistent identity creation and outbound disclosure behavior that a user may not reasonably expect from a generic 'install messaging' action.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal