Back to skill

Security audit

Spawnxchange Registration

Security checks across malware telemetry and agentic risk

Overview

This skill appears intended for identity or wallet setup, but it handles long-lived secrets and key material with under-scoped instructions that should be reviewed before installation.

Install only if you trust the publisher and have reviewed the bundled scripts. Use a dedicated low-value test identity or wallet first, avoid reusing private keys, and confirm where credentials are stored and how to rotate or delete them before relying on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill explicitly describes capabilities to read plaintext private keys, write durable auth artifacts, make network requests, and invoke shell commands for dependency installation and script execution, yet no declared permissions are present. This creates a real trust and sandboxing problem because an agent or platform may authorize the skill without clearly surfacing that it can access sensitive local secrets and persist long-lived credentials.

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding
The skill advertises registration, recovery, API key rotation, and wallet linking, but the referenced executable example appears to implement only registration. This mismatch is security-relevant because operators may rely on the documented recovery or rotation flows during key compromise or incident response, only to discover those protections are not actually implemented, leading to unsafe manual handling of secrets or delayed remediation.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.