Back to skill

Security audit

Graph Query Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is a blockchain query helper, but it asks for broader write and exec authority than its free read-only description justifies.

Review this skill before installing. Its blockchain lookup purpose is understandable and no malicious code was found, but only install it if you are comfortable granting an agent write and command-execution authority for a skill that otherwise presents itself as free and read-only. Prefer a version that removes write permission, narrows exec use, and clearly asks before saving or exporting data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is described as a free, no-wallet, read-only blockchain query tool, yet it requests broad tool privileges including write and exec and documents create/modify/import/save operations unrelated to read-only queries. This mismatch expands the attack surface and can cause an agent to perform unintended local state changes or execute actions beyond the user’s expected trust boundary.

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
The documentation instructs the agent to run generic network-diagnostic commands such as ping and to inspect firewall/proxy connectivity, which is outside the stated blockchain-query purpose. Even if seemingly harmless, this normalizes arbitrary command execution and can be abused for host/network reconnaissance in environments where exec is available.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill explicitly claims the free version never requests a wallet and only reads chain data, but elsewhere it declares write capability and describes modify/import/save behaviors. This contradiction can mislead users and agent frameworks into trusting the skill as read-only while it retains privileges that enable persistence or local data modification.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger condition says to use the skill for broad tasks like data analysis, report generation, statistical insights, and visualization, which exceed the documented blockchain-query routing purpose. Overbroad invocation criteria increase the chance the agent will call this skill in unrelated contexts, exposing unnecessary exec/write capabilities and producing behavior outside user expectations.

Vague Triggers

Low
Confidence
78% confidence
Finding
The capability sections use generic operational verbs such as create, modify, reset, import, export, save, and convert without defining boundaries or tying them to safe read-only query behavior. In an agent setting, ambiguous action language can be interpreted broadly and lead to unintended writes, file handling, or tool invocation beyond the intended scope.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation advertises export/save operations without warning that these actions may write query inputs or results to local files or other persistent storage. In an agent environment, silent persistence can leak sensitive addresses, research targets, or derived datasets and violates expectations for a supposedly free, read-only query tool.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.