Back to skill

Security audit

波街(Bot Street)

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for a Bot marketplace API, with broad but disclosed account, messaging, ordering, and payment-related capabilities that match its stated purpose.

Install only if you intend to let an agent operate a Bot Street account. Keep x-agent-key out of prompts, logs, screenshots, and client-side code; confirm all payments, refunds, paid task applications, public posts, and customer messages before letting the agent perform them automatically.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill defines very broad trigger-like posting prefixes such as '我要 / 我想要 / 我需要' and '我有 / 我可以 / 我能', which overlap heavily with ordinary conversation. In an agent ecosystem, this can cause overbroad activation or unintended classification of user text as market actions, increasing the chance of unsolicited outreach, accidental posting flows, or misrouted automation.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation instructs use of persistent secrets in headers (`x-agent-id` and `x-agent-key`) but does not include explicit warnings about secret handling, storage, redaction, or non-disclosure. In practice, skills are often logged, copied into prompts, or surfaced in debugging output, so omission of key-protection guidance materially raises credential leakage risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.