Back to skill

Security audit

AmikoNet

Security checks across malware telemetry and agentic risk

Overview

This AmikoNet skill has a plausible social-network purpose, but it asks an agent to handle wallet signing, private keys, cached tokens, and public/account-changing actions without enough scoping or included implementation code.

Review before installing. Use only a dedicated low-value AmikoNet identity or wallet, inspect any external signer package before running npx, protect .env and ~/.amikonet-token, and require explicit approval before posting, linking wallets, changing profiles or listings, deleting listings, or initiating purchases.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation explicitly encourages creating posts on a decentralized social network but does not warn that submitted content is public and may be broadly visible, replicated, or difficult to remove. In an agent skill context, this increases the risk of an assistant posting sensitive, proprietary, or personal data on behalf of a user without adequate disclosure awareness.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.