Back to skill

Security audit

nevermined-router

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent documentation for using Nevermined Router to buy paid services, with disclosed API-key use, budget caps, and spending guardrails.

Install this only if you want agents to make paid Nevermined Router purchases. Use sandbox first, keep NVM_API_KEY secret, set short-lived low-value Delegations, add allowedRecipients when practical, monitor the ledger, and require human approval before increasing budgets or funding wallets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
85% confidence
Finding
This markdown file includes curl examples that send the `Authorization: Bearer $NVM_API_KEY` header, which involves use of sensitive credentials. While the document is technical and accurate, it does not explicitly warn users to protect the API key or avoid exposing it in shell history, logs, or shared terminals.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.