Back to skill

Security audit

Crypto Market Data

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk market-data helper, but the published artifact appears incomplete because it documents scripts and references that are not included.

Install only if you are comfortable with a skill intended to call external market-data services. This published version appears incomplete, so verify that the referenced script is actually present before relying on it, and avoid using --out paths that could overwrite important files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broadly phrased around generic crypto market-data tasks and encourages reuse in other projects, which can cause over-triggering by an agent even when a narrower or safer data source would suffice. In an agent ecosystem, overly broad activation increases the chance the skill is invoked in unintended contexts, leading to unnecessary external data access, execution of bundled scripts, and confusion about scope boundaries.

Missing User Warnings

Low
Confidence
81% confidence
Finding
The documentation explicitly demonstrates writing output to an arbitrary file path but does not warn about overwriting existing files or recommend safe file-handling practices. In an agent setting, this can normalize file modification behavior and increase the risk of clobbering local files if an output path is chosen carelessly or influenced by user input.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.