Back to skill

Security audit

hyperbot-quote-mcp

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed remote crypto analytics skill with financial-risk and privacy caveats, but no evidence of hidden access, credential theft, account mutation, or destructive behavior.

Install only if you trust Hyperbot, the remote MCP endpoint, and any npm connector package your client requires. Avoid submitting wallet addresses you consider sensitive, and treat all trading recommendations as informational analysis rather than financial advice or a sole basis for real trades.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill instructs users to install and run external package-manager commands such as `npx -y mcp-remote` and `npm install -g mcporter`. Even if meant for legitimate setup, this expands the trust boundary to arbitrary third-party code execution on the user's machine, which is risky for a skill whose primary purpose is data analytics rather than local software installation.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The prompt template goes beyond passive analytics and instructs the agent to generate copy-trading strategy, follow lists, position sizing, and timing guidance. This broadens the skill from analysis into actionable financial decision support, increasing the chance of unsafe or unauthorized high-impact recommendations.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The whale-tracking prompt directs the agent to infer manipulation signals and provide concrete trading recommendations and entry/exit timing. That exceeds the declared analytics role and can drive users toward speculative actions based on opaque model reasoning and potentially incomplete data.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
These prompts instruct the agent to produce forecasts, sentiment classifications, risk levels, and optimization advice for trading behavior. In context, this turns a data analytics skill into an autonomous advisory engine, increasing the risk of overreach, harmful guidance, and user reliance on unsupported recommendations.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The example workflow operationalizes copy-trading recommendations, including whom to follow and when to enter positions. Concrete examples often become de facto behavior, so this materially increases the likelihood that the agent will provide actionable trading instructions outside the stated remit.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases are broad and map to common user intents like market data, whale tracking, and trader statistics. Loose invocation scope can cause the skill to activate unexpectedly, resulting in unnecessary third-party data transmission or financial-analysis behavior when the user did not explicitly request this skill.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill routes user queries and wallet addresses to a remote MCP endpoint but does not provide a clear, user-facing notice that this data leaves the local environment. Wallet addresses and trading interests can be sensitive, and undisclosed external transmission creates privacy and trust risks.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The prompt reference explicitly instructs the model to generate copy-trading strategy suggestions and actionable recommendations but provides no balancing warning that trading is speculative and may cause financial loss. In a crypto analytics skill, users are likely to treat outputs as financial guidance, so omission of risk disclosures and uncertainty framing can encourage harmful overreliance on model-generated advice.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This prompt asks the model to predict short-term market impact and provide trading recommendations tied to whale movements without warning that such signals are noisy, manipulable, and unsuitable as guaranteed guidance. In the context of volatile crypto markets, users could act on these recommendations and incur losses due to false confidence in model-generated predictions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The market-sentiment prompt directs the model to forecast short-term trends, identify support/resistance levels, and flag catalysts without any warning about uncertainty or risk to capital. Because this skill is specifically marketed for trading analytics, the surrounding context increases the chance that users will rely on these outputs for real-money decisions, amplifying potential financial harm.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.