Back to skill

Security audit

northcap-provider-register

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, user-triggered registration helper that sends provider details to Northcap's public registry, with no hidden execution or local privilege behavior found.

Before using it, assume your agent name, scope, USDC wallet address, and any optional contact or description may be stored by Northcap and associated with a public provider listing. Avoid submitting personal contact details unless you want them tied to that registry.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to send a USDC wallet address and optional contact details to a third-party API, but it does not clearly warn that this information will be transmitted, stored, and potentially published via a public provider registry. Because wallet addresses and contact data can be linked to identity, reputation, and financial activity, users may disclose sensitive information without informed consent.

Static analysis

No suspicious patterns detected.