Back to skill

Security audit

Kannaka Quantum

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed quantum-hardware helper with clear spend safeguards, though users should be careful before enabling paid backends.

Use the free simulator for routine tasks. Before any real QPU run, confirm the backend, expected credits, shot count, and that you intentionally want to use stored qBraid or OpenQuantum credentials. Review the external kannaka-quantum package before installing it with pip.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description is overly broad: it says to invoke the skill when asked to run a quantum circuit, draw quantum entropy, list QPUs, or execute recall, without clearly constraining when paid hardware access, external tool execution, or credential-dependent operations are appropriate. In an agent setting, this can cause the skill to activate for loosely related requests and drive shell/MCP actions that may spend credits or access external providers, increasing the chance of unintended tool use and cost-incurring operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.