PancakeSwap

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only PancakeSwap liquidity-risk review skill that does not run code, access wallets, or request credentials.

Safe to install from an agentic-security perspective. Treat its output as decision support, not financial advice or a smart-contract audit, and verify live pool data, token risk, and market assumptions before deploying capital.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes generic phrases such as "range risk," "concentrated liquidity," and "should I add liquidity," which are likely to appear in ordinary DeFi conversations without a deliberate intent to invoke this skill. This can cause accidental activation, routing sensitive financial prompts into the skill unexpectedly, and increase the chance of prompt-collision or misapplication of the skill's guidance in broader contexts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal