Crypto Portfolio Tracker Pro

Security checks across malware telemetry and agentic risk

Overview

This crypto portfolio skill appears purpose-related, but it may route broad financial requests into under-disclosed exchange, wallet, and alert integrations involving sensitive data.

Review before installing. Use only with read-only exchange keys where possible, never provide seed phrases or withdrawal-enabled credentials, and avoid connecting wallets or notification endpoints until the skill clearly documents what data is sent, stored, and retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The 'Use when' text is broad enough that an orchestrator or user could invoke this skill for generic portfolio-analysis tasks beyond its real capabilities. In a crypto setting, overbroad routing increases the chance that users expose wallet, exchange, or financial context to a tool that cannot safely or accurately fulfill the request, compounding the risk created by the feature mismatch.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill describes exchange, wallet, and alert integrations without warning users that using these features may involve sensitive financial identifiers, API-connected account data, wallet addresses, and notification endpoints. Without clear disclosure and consent boundaries, users may provide or authorize access to sensitive crypto-related data they do not realize will be processed or stored.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal