Back to skill

Security audit

Airdrop Hunter

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real crypto airdrop helper, but it needs Review because it includes anti-abuse evasion guidance and a risky charge-capable payment helper.

Install only if you are comfortable with a paid crypto-focused skill that may contact an external billing service and includes charge-capable code. Do not use its multi-account, proxy, fingerprint-browser, or behavior-variation guidance to bypass project rules, and treat wallet transactions, private keys, seed phrases, bridges, swaps, staking, and contract deployments as high-risk actions that can cause irreversible loss.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises or implies capabilities involving network access, environment-variable reads, and file-writing behavior without declaring the corresponding permissions. Undeclared sensitive capabilities undermine the trust model, prevent informed consent, and can enable hidden data access or persistent side effects if the skill implementation uses them. In this context, the combination is more concerning because the skill also references payment and live data retrieval, which increases the likelihood that these capabilities are actually exercised.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The declared skill purpose is airdrop research and guidance, but the analyzed behavior includes external billing API calls, per-use charging, payment-link generation, reading user identifiers from environment variables, and blocking execution when payment is absent. This is a material description-behavior mismatch that can mislead users into triggering financial transactions and exposing identifiers without clear upfront disclosure or scoped consent. The skill context makes this more dangerous because users seeking informational help would not reasonably expect hidden payment enforcement logic tied to external services.

Missing User Warnings

Medium
Confidence
99% confidence
Finding
A live-looking billing API key is hardcoded directly in the source file and then used for outbound requests. If this code is shared, logged, or committed to a repository, anyone with access could abuse the credential to interact with the billing API, potentially charging users, querying balances, or creating fraudulent payment links.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill attempts to charge the user automatically during verification without explicit consent at execution time. In skill context, this is more dangerous because the function is designed to run at startup, creating a risk of silent or unexpected charges tied only to an environment-supplied user ID.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The checklist tells users to back up wallet private keys or seed phrases but does not emphasize that these secrets must never be exposed digitally or shared. In a crypto-focused skill, this omission is risky because users may interpret it as routine operational advice and store highly sensitive credentials in insecure places, leading to wallet compromise and irreversible asset loss.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
Recommending different IPs to apply for multiple accounts directly promotes account-circumvention behavior designed to evade anti-sybil or anti-abuse controls. In an airdrop-hunting skill, this is especially dangerous because it operationalizes deceptive conduct that can cause account bans, fraud exposure, and policy violations across third-party platforms.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The tutorial directs users to connect wallets, bridge assets, swap, stake, and deploy contracts on multiple third-party sites, but omits basic signing and approval safety guidance. In a crypto airdrop-hunting context, this increases the chance users approve malicious transactions, interact with spoofed dApps, or mis-handle real assets while following the workflow.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The guide suggests preparing multiple addresses and avoiding linkage, but provides no advice on securely managing wallets, seed phrases, browser profiles, or operational separation. In an airdrop-farming skill, this can lead users to unsafe wallet sprawl, privacy mistakes, and accidental loss of access to funds or identities.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The guide encourages users to bridge assets, perform swaps, stake, and deploy contracts, but it does not explicitly warn that blockchain transactions are irreversible and may result in permanent asset loss from user error, malicious contracts, bridge failures, or incorrect network/address selection. In the context of a beginner airdrop guide, this omission is more dangerous because inexperienced users may treat the checklist as routine and underestimate real financial risk.

Ssd 4

Medium
Confidence
95% confidence
Finding
This section explicitly teaches multi-account farming and operational evasion techniques such as IP isolation, fingerprint-browser use, fund segregation, and behavior differentiation to avoid anti-Sybil detection. In the context of an airdrop-hunting skill, this materially increases harm because it operationalizes policy evasion and fraudulent abuse of third-party token distribution systems at scale.

Ssd 4

Medium
Confidence
98% confidence
Finding
The section combines multiple preparatory steps—multiple emails, social accounts, wallets, and varying IPs—to systematically enable deceptive multi-account participation. The cumulative workflow goes beyond neutral information and acts as an operational guide for sybil-style abuse, which is particularly concerning given the skill's stated purpose of optimizing airdrop and whitelist outcomes.

Ssd 4

Medium
Confidence
98% confidence
Finding
This section gives operational advice for separating accounts, combinations, funding relationships, and proxy/IP rotation to reduce linkage across multiple accounts, which materially assists anti-Sybil evasion in airdrop farming. In the context of an airdrop-hunting skill, that guidance is more dangerous because it is directly applicable to bypassing platform abuse controls rather than merely describing risks academically.

Ssd 4

Medium
Confidence
95% confidence
Finding
The recommendation logic explicitly advises users to use multiple accounts, avoid linkage, and vary behavior to reduce detection, which facilitates anti-sybil evasion. In the context of an airdrop-hunting skill that already supports multi-account management, this materially increases abuse potential by operationalizing fraud against third-party platforms' eligibility and anti-abuse controls.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.