Back to skill

Security audit

Aegis Security Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a read-only blockchain safety-check helper, with a privacy note around its quota fingerprint but no artifact-backed malicious behavior.

Before installing, understand that wallet or token addresses you check and the X-Client-Fingerprint header will be sent to the external API. Use a non-sensitive, per-install or otherwise low-identifying fingerprint where possible, and do not provide private keys, seed phrases, or unrelated personal data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs agents to send a stable X-Client-Fingerprint identifier for quota tracking, but does not warn that this creates a persistent cross-request identifier that can enable user tracking and correlation. In an agent context, a 'stable' fingerprint may end up derived from user, device, workspace, or account context and can leak privacy-sensitive linkage to the external API.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.