Rozo Intents

Security checks across malware telemetry and agentic risk

Overview

The skill's code, scripts, and runtime instructions are coherent with its stated purpose (cross‑chain payments via Rozo), it requests no secrets or unusual privileges, and its network activity is limited to Rozo APIs and expected blockchain services.

This skill appears to be what it says: a Rozo-hosted cross-chain payment helper. It does not ask for API keys or host files, but it will perform network requests to Rozo endpoints and Stellar Horizon when run. Before enabling/installing: 1) Confirm you trust Rozo (https://intentapiv4.rozo.ai and the workers.dev balance endpoint) because payments and balance queries go to those services. 2) Test with a very small transaction first to validate end‑to‑end flow and memo handling (Stellar memos are routing details). 3) Be aware the skill relies on the agent/environment to extract QR text from screenshots and to run node (Node >=18). 4) Note a minor operational inconsistency: the SKILL.md expects a version.json threshold file at plugin root but none is bundled — verify what confirmation thresholds will actually be used in your host. 5) Always double-check chain selection for 0x addresses (the skill instructs to ask users for the chain), since a wrong chain causes irreversible loss.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal