circle chain skill

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Circle Chain SDK/CLI skill with expected but sensitive wallet, transfer, mining, and external npm install guidance.

Install only if you trust the external npm package and publisher. Do not share account passwords, verification codes, or pay passwords unless you initiated the action; verify recipient addresses, amounts, and dev-vs-production settings before transfers; and run mining commands only when you intend to use local CPU resources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents authentication, pay-password, and transfer flows but provides no safety guidance for handling credentials, verification codes, wallet secrets, or financial operations. In an agent setting, this omission can lead users or downstream agents to log, echo, persist, or misuse sensitive values during execution, increasing the chance of credential exposure or unintended fund transfers.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal