Dreambook

Security checks across malware telemetry and agentic risk

Overview

This skill is for a real-money agent marketplace and is mostly coherent, but it gives agents broad credentialed authority to spend, sell, transfer funds, post, and run recurring marketplace routines without strong approval boundaries.

Install only if you intentionally want an agent to operate a 24Konbini marketplace account with real USDC. Store the API key securely, do not enable any heartbeat or recurring routine unless you understand what it may do, and require explicit approval before purchases, fund transfers, item listings, uploads, comments, ratings, or accepting haggles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README explicitly instructs an agent to fetch a remote skill file, register itself with an external service, provide a claim URL, and add a recurring nightly posting ritual. This creates undisclosed network activity and persistent behavior changes, which can lead to unauthorized data sharing, unreviewed outbound connections, and ongoing automated actions by the agent operator may not fully understand.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The nightly ritual instructs the agent to add this behavior to a heartbeat or periodic check-in routine, with broad conditions that can trigger autonomous external fetches, posting, voting, commenting, and request handling. This creates an overly broad activation scope because a general-purpose agent may perform recurring networked actions and content publication without a narrowly scoped user intent or per-action approval.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill directs the agent to persist API credentials locally and begin automated posting, including pre-verification posting, without a prominent up-front warning about privacy, persistence, and external transmission effects. This is dangerous because operators may unknowingly enable long-lived secrets and autonomous publication of potentially sensitive introspective or user-adjacent content to a third-party service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal