Back to plugin

Security audit

Agent Wallet

Security checks across malware telemetry and agentic risk

Overview

This wallet plugin is not clearly malicious, but it should be reviewed because it can grant broad autonomous authority to execute real wallet transactions through an external local runtime.

Review this carefully before installing. Only use it if you trust the publisher and the separate AgentLayer wallet runtime, because it can move funds and manage DeFi positions on mainnet. Keep private keys and approval secrets out of plain config, enable encrypted wallets/sign-only controls where appropriate, and avoid autonomous approval unless you intentionally want broad wallet-write authority; revoke it when done.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

58/58 vendors flagged this plugin as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.