Meme Rush

Security checks across malware telemetry and agentic risk

Overview

The provided artifacts describe a public meme-token market-data lookup skill with no install code or credentials, but users should notice its external API calls and unverified provenance.

Before installing, treat this as an informational market-data skill, not a trusted trading or wallet-management tool. Expect requests to Binance Web3 public endpoints, verify the skill's provenance because no source or homepage is listed, and avoid sharing wallet credentials or authorizing financial transactions through this skill alone.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI02: Tool Misuse and Exploitation
Info
What this means

Using the skill may send token keywords, filters, and chain selections to Binance Web3 endpoints, but the artifacts do not show credential use or trade execution.

Why it was flagged

The skill instructs the agent to make external POST requests for token-ranking data. This is disclosed and purpose-aligned, but users should expect their query parameters and filters to be sent to that service.

Skill content
URL: https://web3.binance.com/bapi/defi/v1/public/wallet-direct/buw/wallet/market/token/pulse/rank/list
Recommendation

Use it as a market-data assistant only, review generated requests if shown, and do not provide wallet credentials or authorize trades unless using a separate trusted trading workflow.

#
ASI04: Agentic Supply Chain Vulnerabilities
Low
What this means

A user may not be able to independently confirm who published the skill or whether it is officially affiliated with the service it references.

Why it was flagged

The registry information does not provide a verifiable source or homepage. This does not indicate malicious behavior, especially because no code is installed, but it leaves provenance and affiliation unclear.

Skill content
Source: unknown; Homepage: none
Recommendation

Verify the publisher and API documentation independently before relying on the skill for trading decisions.