Back to skill

Security audit

Crypto Research

Security checks across malware telemetry and agentic risk

Overview

This is a coherent crypto research helper that sends user-directed prompts to CellCog, with privacy caution needed for portfolio and wallet-analysis examples.

Before installing, understand that research prompts are intended to be sent to CellCog using your API key. Use anonymized or approximate holdings when possible, never provide seed phrases or exchange credentials, and independently verify outputs before making financial or tax decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly invites users to paste detailed crypto holdings and total portfolio value, which can expose highly sensitive financial information to a third-party service or model without an accompanying privacy warning or data-minimization guidance. In a crypto context, portfolio disclosures are especially sensitive because they can facilitate targeting, phishing, doxxing, or correlation with on-chain identities.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The skill promotes whale tracking and team research without warning that profiling wallets, founders, or entities may be incomplete, privacy-invasive, or misused for harassment, surveillance, or unsafe financial decision-making. While these activities are common in crypto research, presenting them without guardrails normalizes potentially sensitive attribution and overreliance on inferred identity data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.