Back to skill

Security audit

Ntriq X402 Sentiment Batch

Security checks across malware telemetry and agentic risk

Overview

This is a paid remote sentiment-analysis skill with clear endpoint and payment disclosure, but users should treat submitted text as leaving their environment.

Before installing, treat this as a paid remote API: each call may cost $3 USDC and will send the provided texts to x402.ntriq.co.kr. Use explicit payment approval or a limited wallet, and avoid submitting secrets, regulated data, or sensitive personal or business content unless you trust the provider's handling of that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill clearly instructs users to POST raw text inputs to an external HTTPS endpoint, but it does not prominently warn that submitted content leaves the local environment and is processed by a remote third-party service. This can lead users to send sensitive customer messages, tickets, or internal data under the mistaken assumption that the skill operates locally or without external disclosure, creating privacy, confidentiality, and compliance risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal