Back to skill

Security audit

Near Best Practices

Security checks across malware telemetry and agentic risk

Overview

This is a small static NEAR best-practices CLI with an inflated content-size claim but no evidence of unsafe access or hidden behavior.

Safe to install as a lightweight local NEAR reference tool, but do not treat it as comprehensive or authoritative security documentation; verify high-stakes wallet, contract, and DeFi guidance against official NEAR documentation and current audits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
This is a mismatch because the description materially overstates the scope and content of the skill. The code is indeed a NEAR best-practices reference, but it is not a comprehensive 100+ term guide; it contains only a much smaller hardcoded set of entries. Its primary behavior is a command-line glossary/browser for static terms. While the extra CLI functionality is consistent with a guide, the numerical and comprehensiveness claims in the description are inaccurate enough to make the declared purpose not fully representative of the actual code.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.