INCLAWNCH UBI Staking

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed INCLAWNCH staking guide with public read queries and wallet-signed on-chain transactions, but users should verify transaction details and understand wallet privacy exposure.

Install only if you intend to interact with this specific INCLAWNCH staking contract. Before signing any transaction, verify the Base chain, token address, staking contract address, function, and amount in your wallet. Treat wallet lookups and leaderboard data as public financial/social identity information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill documents a public wallet lookup endpoint and a top-stakers leaderboard without warning that wallet addresses, balances, reward estimates, and linked social identities may expose sensitive financial profiling data. In a crypto staking context, this can facilitate unwanted deanonymization, targeted phishing, and behavioral tracking of users, especially when wallet data is combined with X/Twitter handles and staking history.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal