Venice Admin

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Venice AI admin helper that reads account balance, usage, and API-key metadata, with sensitive but purpose-aligned admin-key access.

Install only if you are comfortable giving the agent access to a Venice Admin API key. Use a dedicated key when possible, avoid shared shells or logs, review exported usage files before sharing them, and rotate the key if the environment is no longer trusted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill declares powerful capabilities in metadata and behavior—environment variable access, network access, and file output via `--output`—but does not declare explicit permissions. This is dangerous because the skill operates with an Admin API key and can transmit sensitive billing and API-key data to an external service while also writing potentially sensitive results to disk without a clear permission model.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal