Back to skill

Security audit

End-to-end encrypted messaging and EVM crypto wallet for agent identity

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-aligned, but it asks an agent to handle wallet private keys and send real cryptocurrency without enough documented safeguards.

Install only if you specifically need OpenIndex messaging plus wallet functions. Use a dedicated low-balance wallet, do not reuse valuable private keys or seed phrases, verify the npm package before running it, clear sensitive environment variables after use, and require manual confirmation of recipient, resolved address, chain, token, amount, and fees before any transfer.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises username-based crypto transfers and token sends without any nearby warning that blockchain transfers are irreversible and that usernames, chains, and token mappings must be verified before sending. In an agent skill, this omission materially increases the chance of misdirected funds, wrong-chain transfers, or mistaken sends to spoofed/similar usernames.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.