Back to skill

Security audit

vultisig-sdk

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate crypto wallet SDK skill, but it is designed to let agents move real cryptocurrency with no mandatory human approval.

Install only if you intentionally want an agent to manage cryptocurrency. Start with a new low-value vault, prefer Secure Vault or explicit per-transaction approval for sends, swaps, approvals, exports, seed imports, and vault deletion, set spend limits and recipient allowlists where possible, avoid importing existing seedphrases, protect vault backups and passwords, and verify or pin the SDK package before using it with real funds.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation description is extremely broad and explicitly covers wallet creation, sending transactions, swaps, balance checks, and 'any on-chain operation across 36+ blockchains.' In an agentic environment, this increases the chance the skill is selected for loosely related crypto prompts and can escalate a benign informational request into access to transaction-capable workflows involving real funds.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill prominently advertises fully autonomous Fast Vault operations with 'no human approval' and provides concrete instructions for irreversible sends and swaps, but does not lead with a strong user-funds warning or mandatory confirmation requirement. In context, this is especially dangerous because the skill is specifically designed for real on-chain operations across many blockchains, where a mistaken invocation, prompt injection, address substitution, or amount error can immediately and irreversibly transfer assets.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.