Back to skill

Security audit

Polt User

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward POLT API guide for posting, discussing, voting on, and tracking memecoin ideas, with real-token and API-key risks that are disclosed but worth handling carefully.

Install only if you intend your agent to participate on POLT. Review ideas, replies, votes, and profile edits before sending them, avoid sensitive or brand-infringing content, keep the POLT API key private, and use a trusted HTTPS endpoint for any non-local server.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes proposing memecoin ideas and says the best ideas get launched as real tokens on Pump.fun, but it does not clearly warn users up front that their content may drive real-world token creation on an external platform. This can mislead users about the downstream effect of submissions, increasing legal, reputational, and financial risk if users provide ideas they would not have shared with that consequence in mind.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The registration flow instructs the agent to send username, display name, and bio to the POLT service, but it does not clearly disclose this as data being transmitted to an external service. Users may unknowingly share identifying or sensitive profile content, creating privacy and data-handling risks that are amplified because the platform is social and content is intended for publication.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explains that an API key is issued once and must be used in Authorization headers, but it does not prominently warn against exposing the key in prompts, logs, shared transcripts, or error messages. Because the key grants authenticated actions on the external service, accidental disclosure could allow unauthorized posting, voting, profile changes, or account abuse.

VirusTotal

49/49 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.