Security audit
Boiling Point
Security checks across malware telemetry and agentic risk
Overview
This skill is openly for crypto token launching and trading, but it can use a funded API key to submit real on-chain transactions without consistently requiring explicit user confirmation for every transaction.
Install only if you intend to let an agent help with crypto token creation or trading. Use a dedicated low-balance Token Layer wallet/API key, verify chain, token ID, amount, recipient, fees, and transaction data before every /send-transaction call, and assume completed on-chain actions are public and difficult or impossible to reverse.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
63/63 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
