Back to skill

Security audit

kog

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-built for a crypto launchpad, but it gives an agent high-impact wallet-signing and public identity-publishing workflows without enough consent and privacy guardrails.

Install only if you are comfortable with an agent helping prepare and sign Solana launch transactions and publish marketplace or social identity information. Use a dedicated wallet with limited funds, review every transaction in your wallet before signing, and avoid sharing personal contact details or linking a private Twitter/X account unless you intend that association to be public.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill gives step-by-step instructions to create, sign, and send Solana transactions, including generating a mint keypair and signing with both the mint and user wallet, but it does not warn that these actions can irreversibly spend funds, create on-chain assets, or expose users to malformed or malicious transaction flows. In a wallet-integrated agent context, omission of explicit confirmation and safety guidance materially increases the risk of users authorizing blockchain actions they do not fully understand.

Missing User Warnings

Low
Confidence
83% confidence
Finding
The marketplace registration and update flows encourage submission of email, Telegram, Twitter handle, description, and wallet data without warning that this information may be stored, linked, or publicly exposed through the marketplace. This creates privacy and deanonymization risk, especially because wallet addresses can be correlated with public blockchain activity.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The playground endpoint is described as open chat with optional wallet and author label, but the skill does not warn that submitted content and labels are likely publicly visible and potentially attributable. Users may disclose sensitive information, operational details, or wallet-linked identities in a public, indexable channel without realizing the exposure.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is written as a broad API reference with expansive language such as 'Use this document as the single source of truth' and 'What you can do,' but it does not define clear activation boundaries or user-consent preconditions. In an agent setting, this can cause the skill to be invoked too broadly for actions involving token launches, marketplace registration, social verification, and on-chain transaction preparation, increasing the chance of unintended high-impact actions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The marketplace registration flow encourages submission of wallet addresses, email, Telegram, Twitter handle, description, and tags for public listing, but does not clearly warn that this creates a public, searchable profile. Users may unknowingly expose identity-linked contact and wallet data, enabling profiling, deanonymization, scraping, or targeted phishing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The Twitter/X verification flow instructs the user to post a public verification tweet containing a code and then bind that account to the provider profile, but it does not clearly warn that this publicly links the Twitter/X account to the agent identity and marketplace record. That linkage can permanently reduce anonymity and facilitate tracking, impersonation targeting, or reputation attacks.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.