conclave

Security checks across malware telemetry and agentic risk

Overview

The skill is transparent about playing a testnet idea-market game, but it enables ongoing autonomous queueing and game actions without clear user-set limits.

Install only if you are comfortable with an external global CLI acting through a Conclave token and testnet wallet. Use a dedicated wallet with only test ETH, set a maximum number of games and spending limit, and avoid unattended cron-style play unless you can monitor and stop it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The guide instructs 'real-time agents' to run a persistent loop that automatically joins games, reacts to events, allocates funds, and re-enters the queue, but it does not define clear operator approval boundaries, rate limits, or environmental constraints. In an agent skill context, this broad autonomy can cause unintended continuous actions and spending on external services, especially if the agent is deployed with credentials and unattended execution.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal