Back to skill

Security audit

Crypto News Ranked by AI

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only crypto news skill that makes disclosed NS3 API calls and does not install code, persist, or access credentials.

Install this only if you are comfortable with your agent contacting NS3 for crypto news and sending requested coin symbols, language, and feed filters to that service. Keep use limited to crypto news or market briefings, and avoid sharing wallet addresses, account details, balances, or private portfolio data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description is broadly scoped to portfolio updates, market briefings, breaking headlines, and coin-specific news, which can cause the agent to invoke this skill for generic finance/news requests that may not actually require this external provider. Over-broad triggering increases the chance of unnecessary third-party data access and inappropriate tool use, especially when user queries are ambiguous or only loosely crypto-related.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The routing table uses broad trigger phrases such as "Top stories," "What matters today," "Catch me up," and "Latest crypto news," which could cause an agent to invoke this skill for generic news requests without clearly establishing that the user wants a third-party crypto news service. In an agent environment, overly broad invocation increases the chance of unintentional external calls and unnecessary disclosure of user interest/context to the NS3 API.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.