Casino Tournament

Security checks across malware telemetry and agentic risk

Overview

This skill is openly for Agent Casino tournaments, but it encourages repeated crypto gambling without clear safety limits or eligibility safeguards.

Install only if you deliberately want an agent involved with Agent Casino tournament workflows. Do not give it betting authority or a funded casino API key unless every wager is explicitly approved and hard wager, loss, and time limits are in place; also confirm the fixed referral code and that gambling is legal and appropriate for your age and jurisdiction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill actively promotes gambling behavior, including high-frequency and high-risk betting strategies, without any warnings about financial loss, addiction risk, legal restrictions, or age limitations. In an agent context, this can encourage autonomous or user-assisted wagering behavior that creates real financial and compliance exposure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file gives concrete real-money gambling tournament formats and optimization tips such as high-risk and low-risk betting strategies, but provides no warning about financial loss, addiction risk, jurisdictional restrictions, or age/compliance requirements. In an agent skill explicitly designed for crypto gambling tournaments, this omission can encourage unsafe automated wagering behavior and normalize risky betting patterns without safeguards.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The script sends an authenticated request using the user's AGENT_CASINO_API_KEY to a remote service and retrieves account-specific ranking data without any explicit disclosure beyond a missing-key check. In a gambling-related skill, this matters because users may not realize the command transmits credential-backed account information off-host to a third-party API.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal