Back to skill

Security audit

DappLooker AI

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed paid DappLooker DeFi data integration with spending safeguards and no executable install code or hidden persistence found.

Install only if you are comfortable sending token symbols, contract addresses, market questions, and free-form strategy prompts to DappLooker and paying small USDC fees for approved calls. Confirm the endpoint, cost, payment network, and session budget before use, avoid sending private portfolio or proprietary trading details, and independently verify trading recommendations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill hard-codes a specific payment rail and states that payments must always use Polygon/USDC because the user's wallet is only funded there. This can steer an agent into making paid actions under assumptions about wallet funding and network choice that may be false, reducing user control and increasing the risk of unauthorized or unintended spending.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.