Back to skill

Security audit

TWZRD Trust

Security checks across malware telemetry and agentic risk

Overview

The skill is payment-adjacent and mostly transparent, but it asks agents to execute commands supplied by a remote service inside a payment workflow, so users should review it before installing.

Install only if you want TWZRD involved in x402 seller checks. Treat paid trust calls, AgentCash commands, MCP setup, and any next_action.command returned by TWZRD as actions to inspect and approve explicitly before execution, especially when a wallet is funded.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list contains broad, common phrases such as 'before paying', 'check seller', and 'is this wallet safe', which can cause the skill to activate in contexts far beyond explicit requests to use this specific TWZRD workflow. Over-broad activation can route users into unnecessary external calls, payment-related flows, or trust decisions when the user did not intend to invoke this skill, increasing the risk of unintended actions and prompt-surface hijacking.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.