Back to skill

Security audit

Ponzu Launchpad

Security checks across malware telemetry and agentic risk

Overview

The skill’s external metadata hosting guidance appears aligned with its NFT metadata purpose, but its privacy wording should be clearer about optional third-party services.

Before installing, confirm whether you will use Pinata, Arweave, or other HTTPS metadata hosts, and treat any uploaded NFT metadata as shared with those services. Store any Pinata credentials securely and avoid placing private or sensitive content in published metadata.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document states 'No telemetry, analytics, or external API calls' in its security section, but later recommends using Pinata HTTPS endpoints and arbitrary https:// or Arweave URLs for metadata handling. This is a security-relevant contradiction because users may trust the earlier claim and underestimate that the workflow can involve third-party network services, metadata hosting, and disclosure of content or credentials such as a Pinata JWT.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.