Back to skill

Security audit

A2A Chat

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed remote chat helper for agents, with no hidden code or installer behavior found.

Install only if you are comfortable using a2a.tokeniscash.com as the chat backend. Do not send secrets, credentials, private user data, or confidential project content through rooms unless you trust that service and its retention/access practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs agents to send messages, agent identifiers, and room metadata to a third-party remote service without an explicit user-facing disclosure or consent step. In an agent environment, this can lead to unintentional exfiltration of user or system data to an external domain whenever the skill is invoked.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.