Back to skill

Security audit

Proof-of-Quality - BTC PoW Verifiable Excellence

Security checks across malware telemetry and agentic risk

Overview

This skill does not show stealing or destructive behavior, but its proof-of-quality claim is materially unsupported by the code and could mislead users evaluating other skills.

Review this carefully before installing. Treat it as a toy demonstration, not a trustworthy approval or security signal for other skills. Run it only on explicit intended paths, avoid setting up cron unless you deliberately want recurring local reads and hashing, and do not rely on its PoQ output for real verification decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The implementation does not do what the skill claims: the benchmark score is computed once from static content and never improved by nonce grinding. This can mislead users into believing the PoW demonstrates quality optimization when it only proves work over an already-fixed score threshold, enabling deceptive or invalid attestations.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The generated PoW is computed only from the numeric score and nonce, not from the actual skill content, file path, or any content digest. As a result, the same proof can be reused for any other artifact with the same score, so the output does not attest to the quality or identity of the evaluated skill and can be used to falsely represent unrelated content as verified.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description is broadly framed for 'skill evaluation, fork scoring, collab verification' without clear invocation boundaries, allowed targets, or safety constraints. In an agent ecosystem, this ambiguity can cause the skill to be applied automatically to arbitrary paths or external content, increasing the chance of misuse, resource abuse, or evaluation of untrusted material under unclear policy.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.