Binance Sports Ai Analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Binance sports prediction helper with an optional, confirmation-gated trading handoff.

Only install this if you are comfortable using Binance-hosted endpoints for sports prediction data and understand that any prediction-market trading happens through a separate wallet integration. Treat the analysis as informational, verify trade details yourself, and never approve a wallet order unless the outcome, side, amount, cost, slippage, and quote expiry are clear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The file explicitly instructs the agent to use `market-detail-by-slug` when preparing a trade and to hand off market identifiers to wallet/order-placement commands, but it does not pair this workflow with a comparably clear warning that the next steps may trigger financial or account-impacting actions. Although prediction and recompute endpoints include an investment-advice disclaimer, the trade-preparation section lacks a direct safety boundary, which increases the risk that an agent may proceed too seamlessly from analysis into transaction-enabling behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal