Security audit
Ntriq World Bank Economic Indicators
Security checks across malware telemetry and agentic risk
Overview
This economic-data skill is simple and non-executable, but it needs review because it advertises “free” access while directing agents to a paid USDC-per-call endpoint without explicit spending controls.
Install only if you are comfortable with a crypto pay-per-use API. Require confirmation before paid calls or set a clear spending cap, and do not interpret the “free API” wording as meaning zero cost.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
59/59 vendors flagged this skill as clean.
