Security audit
Agent Wallet
Security checks across malware telemetry and agentic risk
Overview
This wallet plugin is not clearly malicious, but it should be reviewed because it can grant broad autonomous authority to execute real wallet transactions through an external local runtime.
Review this carefully before installing. Only use it if you trust the publisher and the separate AgentLayer wallet runtime, because it can move funds and manage DeFi positions on mainnet. Keep private keys and approval secrets out of plain config, enable encrypted wallets/sign-only controls where appropriate, and avoid autonomous approval unless you intentionally want broad wallet-write authority; revoke it when done.
SkillSpector
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
58/58 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
