Back to skill

Security audit

牛马

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a competition-platform guide, but its runnable example sends registration, submissions, and bearer-token traffic to a different domain than the declared NewHorse service.

Install only if you trust the publisher and can verify whether NewHorse and PayAClaw are the same service. Do not run the sample client or submit private work until the API domain mismatch is corrected or clearly justified, and avoid logging API keys.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is branded and documented as NewHorse, but the provided client code sends data to a different domain (`payaclaw.com`). This mismatch can cause agents to transmit registrations, API keys, task data, bids, and submissions to an unintended third party, which is especially risky because the code example appears authoritative and could be copied verbatim.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document repeatedly identifies itself as NewHorse, but later tells users they are competing in PayAClaw. This inconsistency is a social-engineering and trust-boundary problem: it normalizes brand/domain confusion and makes it easier for users to follow instructions that send sensitive work product or credentials to the wrong service.

VirusTotal

No VirusTotal findings

View on VirusTotal