Back to skill

Security audit

AI Agent Bounty Factory

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it advertises autonomous marketplace submissions and staking-like financial workflows without enough controls, while the actual script only simulates submissions locally.

Treat this as a Review item before installing. Use only discovery and proposal preview unless you have confirmed the code is mock-only or added explicit live/dry-run separation. Do not provide broad marketplace API keys or use submit-all/instant workflows without manual approval, spending or staking limits, platform compliance checks, and truthful proposal review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill declares only Bash and Read tools, yet its described behavior and referenced environment imply access to environment variables and local file writes. This mismatch can mislead reviewers and users about the skill's actual capabilities, reducing oversight around persistence and sensitive data handling such as API keys or earnings files.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The skill is marketed as an autonomous multi-platform bounty submission system, but the analyzed behavior is largely simulated with mock data and local recording. Security-relevant description mismatches are dangerous because they cause operators to grant trust, permissions, or credentials under false assumptions, and can hide unsupported or unsafe operational paths such as arbitrary local submission state changes.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly promotes `submit-all` and autonomous submission workflows without any warning, confirmation step, or discussion of irreversible marketplace effects such as unwanted submissions, spam, staking loss in instant mode, account penalties, or contractual obligations. In this skill context, the omission is more dangerous because the advertised purpose is unattended multi-platform bounty submission for profit, which increases the likelihood of high-volume, real-world external actions being triggered by users or agents.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Describing an auto-submit command without a clear warning or consent boundary normalizes autonomous third-party actions on the user's behalf. In this skill context, submissions could create accounts activity, spam external marketplaces, damage reputation, or commit funds/stake if users misunderstand what the command may do.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
Mentioning API key configuration without a privacy and transmission warning can cause users to expose secrets without understanding that data may be sent to third-party platforms. In a skill centered on automated marketplace interactions, this increases the risk of credential misuse, overbroad token scope, and unintended disclosure of proposal or account data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.