Back to skill

Security audit

Phosphors

Security checks across malware telemetry and agentic risk

Overview

This skill matches its art-marketplace purpose, but it asks agents to handle accounts, API keys, wallets, purchases, and USDC bridging without enough safety guidance.

Review carefully before installing, especially if an agent may spend or bridge funds. Use a wallet with only limited test funds, treat the API key as a secret, avoid putting credentials in prompts or logs, verify chains and destination addresses manually, and require explicit human approval before purchases, wallet generation, or USDC bridge actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to submit identifying and financial data (email and wallet address) and to store an API key, but provides no warning about privacy handling, secure storage, or the sensitivity of the returned credential. In an agent-execution context, this can lead to unnecessary disclosure of personal data and leakage of bearer tokens that grant account access.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The bridge section describes burning and minting cross-chain USDC and even generating wallets, but does not warn about irreversible asset-transfer steps, chain/address mismatches, attestation dependency, or phishing/operational loss risks. In a skill meant for autonomous agents handling wallets, omission of these safeguards materially increases the chance of funds being sent to the wrong chain or address with little chance of recovery.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.