Back to skill

Security audit

Veillabs Integration

Security checks across malware telemetry and agentic risk

Overview

This is a coherent crypto API skill, but it can set up fund-moving swap and distribution workflows without explicit confirmation or clear risk and privacy disclosures.

Install only if you trust the Veillabs publisher and the configured VEILLABS_BASE_URL. Before any swap or seed distribution, require the agent to show the exact source and destination assets, networks, amount, recipient addresses, split percentages, expected output, deposit address, and API URL, then approve manually. Treat deposits as irreversible and assume wallet and transaction metadata may be visible to Veillabs, providers, and public blockchains.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to create cryptocurrency swaps and multi-destination fund distributions without any user-facing warning, confirmation step, or acknowledgment that these actions transfer assets and may be irreversible. In a crypto context, missing transaction-risk disclosure materially increases the chance of accidental loss, fraud enablement, or unintended movement of funds.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill documentation instructs an agent to create swaps and seed distributions that can move crypto assets irreversibly, but it does not include a clear safety warning or user-confirmation requirement before submitting requests. In this context, the skill handles wallet addresses, amounts, and transaction tracking with an external service, so omission of explicit warnings increases the risk of accidental asset loss, privacy leakage, and unsafe autonomous execution.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The example workflows operationalize asset-moving actions and status polling without telling the operator to verify destination addresses, networks, and amounts immediately before submission. Because blockchain transfers and swap setups are typically irreversible and errors in addresses or chain selection can permanently lose funds, this omission is materially dangerous in a crypto-transaction skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.