Binance Crypto Market Rank

Security checks across malware telemetry and agentic risk

Overview

This skill fetches public Binance Web3 crypto ranking data and does not show credential access, persistence, or account-changing behavior.

Install this only if you want the agent to run a local shell script that contacts Binance Web3 public APIs for live crypto ranking data. Treat the output as market data, not financial advice, and verify publisher provenance if official Binance affiliation matters to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
76% confidence
Finding
The description is broad enough to trigger on general market-trend or ranking questions, which can cause over-invocation of a skill that performs external requests and script execution. In this context, broad routing increases the chance the skill runs when the user did not intend to authorize networked/scripted behavior.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The documentation explicitly instructs the agent to 'execute scripts immediately' and 'run the script NOW,' while not warning that this will initiate external network access. This is dangerous because it pressures automatic action on adversarial documentation and bypasses normal consent and review boundaries for tool use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal