OpenMM Portfolio

Security checks across malware telemetry and agentic risk

Overview

This skill appears legitimate, but it needs review because it gives an agent broad access to a crypto trading CLI while handling exchange account credentials.

Install only if you intend to let an agent query exchange accounts through OpenMM. Use read-only exchange API keys where possible, disable withdrawals and trading scopes unless explicitly needed, restrict keys by IP when supported, and require explicit user confirmation before any order creation, cancellation, or trading strategy command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to configure exchange API credentials and use commands that query balances and orders, but it does not clearly warn that these actions send authenticated account data requests to third-party exchanges and may expose sensitive financial metadata. In a portfolio-management context, this omission can mislead users into treating the skill as local-only or low-risk, increasing the chance of unintended disclosure or unsafe credential use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal