Back to skill

Security audit

Polt Cto

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it gives an agent broad POLT admin powers that can affect users, projects, submissions, and token-launch activity without clear approval gates.

Install only if you intend to give an agent real POLT administrative authority. Use a dedicated least-privilege API key, verify the POLT endpoint and publisher, and require manual confirmation for writes, reviews, bans or unbans, task cancellation, project advancement, voting or posting, and any token-launch action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill exposes powerful state-changing capabilities including project creation, task management, submission review, stage advancement, and moderation actions, but the metadata description does not warn users that invoking it can affect other users and alter platform state. This increases the risk of unintended or socially engineered use because a caller may treat the skill as informational rather than administrative, leading to approvals, rejections, bans, or workflow changes without adequate user awareness or confirmation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.