Binance Event Contract Data Fetcher

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Binance public market-data fetcher with continuous background polling, but it does not request trading authority, credentials, or private data.

Install only if you want 24/7 background Binance API polling for BTC/ETH market data. Confirm how your agent disables the recurring task, and do not rely on the skill’s accuracy wording as a trading guarantee.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill is explicitly designed to auto-run every minute and continuously access an external Binance API, but it does not present a clear user-facing disclosure, consent step, or runtime indication that recurring outbound network activity will occur. In an agent environment, silent continuous polling can create privacy, operational, and governance risks by surprising users, consuming resources, and leaking usage patterns or environment metadata through repeated external requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal