Security audit
Pinata ERC-8004
Security checks across malware telemetry and agentic risk
Overview
This is a high-risk but clearly disclosed blockchain/IPFS registration skill with scoped credentials, confirmations, and guardrails.
Install only with a dedicated low-balance wallet and a restricted or dedicated Pinata token. Confirm transactions, NFT transfers, uploads, and deletions only after checking the full network, contract, token ID or CID, destination address, and estimated cost.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
