Back to skill

Security audit

Emily - Your Radix Assistant

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Radix blockchain lookup assistant with ordinary third-party API and npm package trust considerations, but no evidence of hidden, destructive, or unrelated behavior.

Install only if you are comfortable installing mcporter from npm and sending Radix wallet addresses, .xrd domains, token identifiers, and market or DeFi queries to the Emily service and its listed data providers. Avoid querying addresses you consider personally sensitive unless you trust those services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports wallet balances, transaction history, RNS resolution, and LP position lookups against external services, but it does not clearly warn users that their wallet addresses and related financial activity will be transmitted to third-party APIs. Even though blockchain addresses are public on-chain, linking a user-supplied address to their current session and querying multiple external providers can create avoidable privacy leakage and profiling risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.