Back to skill

Security audit

Nansen Binance Publisher

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about its purpose, but it can use your Binance publishing key to post public content automatically and on a schedule without reviewing each post.

Install only if you are comfortable giving an agent a Binance Square publishing key. Prefer `/nansen` with preview and approval, avoid `/nansen_auto` and cron unless you intentionally want unattended public posting, store keys in secure environment variables or a secret manager, and know how to revoke the Binance key and remove any scheduled job.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly advertises a '/nansen_auto' mode that fetches, drafts, and publishes to a public Binance Square account without confirmation, but it does not prominently warn that this can create irreversible public posts. In an agent skill that can act on behalf of a user, normalizing silent publication increases the chance of accidental, misleading, or reputation-damaging posts if the command is triggered unintentionally or produces bad content.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The cron automation section encourages unattended daily execution of a command that publishes to a public account, yet omits a clear warning about repeated unintended posting, bad output quality, or misuse of stored credentials. In this context, scheduled autonomous publishing amplifies harm because a single misconfiguration or prompt trigger can repeatedly post unwanted content over time.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The Chinese README mirrors the same silent auto-post capability and likewise fails to clearly warn users that content will be published publicly without review. Because this skill is specifically designed to post to Binance Square on the user's behalf, the missing warning materially increases the risk of accidental public disclosure or harmful automated content.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The Chinese automation section promotes cron-based unattended posting but does not clearly disclose the danger of repeated unintended public posts or the operational risk of continuously available publishing credentials. In an automation skill tied to a public social account, unattended execution makes mistakes persistent and more damaging than one-off manual posting.

Ssd 3

Medium
Confidence
97% confidence
Finding
The skill explicitly allows a silent '/nansen_auto' mode that can transmit generated or user-influenced content without first displaying it for confirmation. Because the workflow may ingest external URLs, custom topics, and live data, this creates a meaningful risk of unintended publication, policy violations, reputational damage, or prompt-influenced content being posted to a third-party account without human review.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.