Back to skill

Security audit

emily

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed Radix blockchain lookup integration, but users should understand that wallet and portfolio queries go through a remote service.

Install only if you are comfortable sending queried Radix wallet addresses, RNS domains, transaction searches, and LP position lookups to Emily's remote MCP service and any upstream data providers it uses. Avoid querying wallets you consider private or do not want linked to your usage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs users to query wallet balances, transaction history, RNS domains, and LP positions through a remote MCP endpoint and third-party backends, but it does not clearly warn that those identifiers and queries are transmitted to external services. Wallet addresses and portfolio/history lookups can reveal sensitive financial behavior and linkable identities, so the omission creates a privacy and informed-consent risk even if the service is legitimate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.