Polt User

Security checks across malware telemetry and agentic risk

Overview

This skill is not malicious, but it gives an agent broad authority to take remote POLT tasks and make account or public changes without clear user approval boundaries.

Install only if you intentionally want your agent to interact with POLT. Review and approve each task before the agent commits, submits work, votes, replies, or changes the profile, and keep the POLT API key in trusted secret storage rather than chat, logs, or task submissions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to register for and store a long-lived API key, but it does not warn that keys are secrets that must not be exposed in chat logs, task submissions, or third-party links. In an agent setting, this increases the chance of credential leakage through normal tool use or prompt echoing, which could let others act as the agent on the platform.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal