Back to skill

Security audit

区块链全能助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed blockchain assistant with no hidden execution, persistence, credential collection, or install-time behavior.

Before installing, be aware this skill may activate on broad crypto terms and its outputs can involve high-risk financial or smart-contract topics. Treat market, yield, and contract guidance as informational, verify on-chain facts independently, and never provide private keys, seed phrases, wallet passwords, or signing authority.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad terms such as "BTC," "ETH," "DeFi," "crypto," and "blockchain," which are common in many unrelated conversations. This can cause the skill to activate unintentionally, increasing the chance of the assistant entering a high-risk blockchain guidance mode when the user did not explicitly request it, including discussion of financial or contract-security topics.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list includes many broad, high-frequency terms such as BTC, ETH, DeFi, Web3, crypto, and blockchain. This can cause the skill to activate in ordinary conversation that only casually mentions these topics, expanding the skill’s reach beyond clear user intent and increasing the chance that its specialized instructions override a more appropriate default assistant behavior.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
Setting Chinese as the default reply language without explicit user choice can lead to responses in an unexpected language, which may confuse users and create policy or usability issues around language preference. While not a direct security exploit, it can degrade clarity in a domain involving financial and contract-risk discussions where misunderstanding matters.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.