Meme Token Analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed crypto token analysis wrapper that uses a remote MCP service, with no local executable code or hidden local access in the supplied artifacts.

Install only if you are comfortable sending token queries and an agent_id to Antalpha's remote MCP service. Keep the agent_id scoped and monitored for metered usage, avoid entering private information in prompts, and treat the token ratings as entertainment or research context rather than buy/sell advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes broad, ambiguous phrases such as "代币评级" and "wealth gene" that can match ordinary conversation rather than an explicit user request to invoke this skill. In an agent environment, overly broad activation boundaries can cause unintended tool execution on financial topics, leading to unsolicited analysis, unnecessary external calls, and increased risk of acting on sensitive investment-related context without clear user intent.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal