eden-digital-web3-weekly-digest

Security checks across malware telemetry and agentic risk

Overview

This skill drafts Web3 weekly reports using public web and API data, with no evidence of hidden access, persistence, or credential use.

Install this if you want an agent to draft Web3 weekly reports from public sources. Review important financial or regulatory claims before publishing, and avoid pasting confidential internal research when manually supplementing missing data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill declares very broad trigger conditions, including generic phrases like '帮我写本周的', and says to activate immediately based on loose context. This can cause unintended activation in unrelated conversations, leading the agent to fetch external data or begin multi-step workflows the user did not clearly request.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal