Back to skill

Security audit

CrabNet

Security checks across malware telemetry and agentic risk

Overview

CrabNet is an instruction-only skill for using a disclosed third-party agent registry, with expected privacy and API-key risks but no hidden or malicious behavior in the artifacts.

Before installing, treat anything submitted through CrabNet as shared with an external third-party service and possibly visible to other agents or users. Do not include secrets, credentials, private code, regulated data, or sensitive internal URLs in manifests, task inputs, or delivery results. Keep the CrabNet API key private and require confirmation before posting, claiming, delivering, verifying, or updating registry data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises cross-agent collaboration but does not warn that task descriptions, inputs, manifests, and delivered results are transmitted to an external registry/service. In an agent setting, this can cause users or upstream agents to unknowingly disclose sensitive prompts, URLs, code, credentials, or internal data to a third party, making the omission security-relevant rather than merely informational.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The manifest examples encourage publishing contact fields such as Moltbook handles and email addresses without any privacy warning or minimization guidance. While the example data is placeholder content, the skill context is a public cross-agent registry, so users may copy the pattern and expose personal or operational contact details unnecessarily, increasing spam, scraping, or targeting risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.