Nansen Smart Alerts

Security checks across malware telemetry and agentic risk

Overview

This is a normal Nansen alert-management skill, with ordinary caution needed for deleting alerts and sending alert payloads to webhooks.

Install this only if you want the agent to manage Nansen smart alerts using your NANSEN_API_KEY. Confirm alert IDs before deletion, prefer disabling over deleting when unsure, and send webhooks only to trusted HTTPS endpoints because alert payloads may reveal monitored tokens, addresses, or operational strategy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents `nansen alerts delete <id>` as a first-class operation but provides no warning, confirmation step, or guidance to verify the target alert before deletion. In an agent context, this increases the chance of accidental destructive actions, especially when IDs are ambiguous or user intent is inferred incorrectly.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explains that `--webhook <url>` will POST alert payloads to any public HTTP/HTTPS endpoint, but it does not warn that this transmits potentially sensitive operational or internal alert data to third-party infrastructure. In an agent setting, this can lead to unintentional data exfiltration, misrouting of notifications, or disclosure to attacker-controlled endpoints.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal