Back to skill

Security audit

Kannaka Quantum

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly transparent about its quantum and qBraid Lab features, but it includes high-impact remote compute, SSH agent launch, API-key injection, and destructive environment commands without enough user-control guidance.

Install only if you intend to let the agent manage qBraid Lab resources and remote coding agents. Before using it, confirm every paid compute start, SSH setup, API-key injection, remote agent launch, environment deletion, and kernel removal; list targets first and stop paid compute explicitly when done.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation description is overly broad and authorizes use not just for narrow quantum-circuit tasks, but also for provisioning compute and launching autonomous remote coding agents over SSH. That increases the chance the skill is invoked for loosely related requests and then escalates into remote code execution, infrastructure manipulation, or spend-incurring actions without sufficiently specific user intent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill advertises destructive environment-management commands such as lab-delete-env and kernel removal without pairing them with a user-facing warning or confirmation requirement in the description. In a skill that also supports remote instances and autonomous agents, this omission raises the risk of accidental deletion, disruption of active environments, or loss of reproducibility/data needed by the user.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.