Gambling

Security checks across malware telemetry and agentic risk

Overview

This skill openly enables real-money crypto gambling, but it lacks safeguards before deposits, bets, and withdrawals.

Install only if you intentionally want an agent to access a real-money crypto gambling service. Use a limited wallet, require explicit approval for every deposit, bet, and withdrawal, set strict loss limits, and confirm gambling and crypto transfers are legal for the user and jurisdiction. Be aware the registration example includes a referral code.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Low
Confidence
83% confidence
Finding
The skill includes an affiliate/referral feature that is outside the core gambling gameplay capability and creates a financial incentive for the agent or operator to drive user gambling activity. In a real-money crypto gambling context, that incentive can bias agent behavior toward promoting betting volume rather than acting in the user's best interests.

Missing User Warnings

High
Confidence
97% confidence
Finding
This skill enables deposits, wagers, and withdrawals of real cryptocurrency but does not prominently warn that actions can irreversibly lose user funds, may violate local law, and involve gambling risk. In an autonomous-agent setting, missing safety gating is especially dangerous because the skill normalizes direct money movement and betting without requiring confirmation, limits, or responsible-gambling safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal