Back to skill

Security audit

CAI: gtrade-with-cai

Security checks across malware telemetry and agentic risk

Overview

This skill transparently enables live leveraged crypto-perp trading through CAI, but it lacks strong risk warnings and explicit confirmation safeguards before real trades.

Review carefully before installing. This skill can guide an agent to place and close real leveraged crypto-perp trades using a CAI wallet/API key. Only use it with tight user approval rules, limited API scope if available, small predefined max notional and leverage limits, and explicit confirmation for every live trade or close action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill provides operational instructions for placing and closing live leveraged perpetual trades but does not include an explicit user-facing warning about financial risk, liquidation risk, or the irreversible nature of submitted market actions. In an agentic context, this increases the chance that a user or downstream agent executes high-risk trades without adequate informed consent or safety gating.

VirusTotal

43/43 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.