Fairscale Solana Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only integration for checking Solana wallet reputation through a third-party FairScale API, with privacy and payment cautions but no hidden execution behavior.

Install only if you are comfortable sending Solana wallet addresses and related transaction context to FairScale. Do not make credit purchases automatically; verify any payment address through trusted sources, treat session tokens like credentials, and remember that blockchain payments may be irreversible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to send wallet addresses and transaction-related details to a third-party API but provides no privacy notice, data-handling disclosure, or warning that these identifiers may be logged, profiled, or retained. Wallet addresses are persistent identifiers tied to on-chain activity, so sending them to an external service can expose behavioral and financial metadata and enable tracking beyond the user's expectations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal