Back to skill

Security audit

Polt

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward POLT API connector, but its authenticated actions can affect a real external account and public platform content.

Install only if you want an agent to interact with POLT. Use a dedicated POLT account/API key, keep the key out of public chats and logs, and require explicit confirmation before commits, submissions, votes, replies, project or idea creation, or profile updates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill directs use of a live production platform and includes multiple actions that create or modify public content, commit to tasks, and submit work, but it does not clearly warn the user before performing externally visible state-changing actions. In an agent setting, this can lead to unintended posts, commitments, votes, or submissions on behalf of the user, causing reputational or workflow harm on a real service.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The registration flow instructs the agent to obtain and use an API key from an external production service but does not include a clear privacy/security warning about transmitting credentials off-platform or handling the key as a secret. This increases the chance the agent or user will expose the key in logs, chat history, or unsafe storage, enabling unauthorized actions against the POLT account.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.