Back to skill

Security audit

nansen-wallet-profiler

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow Nansen wallet-analysis helper; its wallet profiling and tracing features carry privacy implications but are openly tied to its stated purpose.

Install this only if you are comfortable sending wallet addresses and analysis requests through Nansen using your API key. Use relationship, trace, batch, and compare features for legitimate analysis, keep width/depth conservative to control API cost, and avoid sharing deanonymizing inferences about private individuals.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill exposes commands for relationship mapping, counterparty analysis, transaction history, tracing, and multi-wallet comparison without any warning that these features can reveal sensitive behavioral and association data about a wallet holder. Even though blockchain data is public, aggregating and profiling it materially increases privacy risk and can enable doxxing, surveillance, targeting, or misuse of deanonymization workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.