Back to skill

Security audit

Dynamix

Security checks across malware telemetry and agentic risk

Overview

This skill matches its crypto-trading purpose, but it needs review because it normalizes private-key exposure and unattended real-money automated trading without strong safety warnings.

Install only if you intentionally want help using Dynamix for live Solana trading. Prefer a new low-balance wallet, avoid importing a primary wallet, verify the platform and deposit address yourself, review buy limits and stop-loss settings, and make sure you know how to stop the bot before funding or starting it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs users to paste a base58-encoded private key into the platform without a prominent warning that this secret grants full control over funds. In the context of a live trading platform, normalizing direct secret entry into a third-party dashboard materially increases the risk of wallet compromise, phishing, and irreversible asset theft.

Missing User Warnings

High
Confidence
99% confidence
Finding
The skill describes a feature that reveals and allows copying a decrypted private key, but does not foreground that anyone who sees or copies that key can immediately drain the wallet. Because cryptocurrency transfers are irreversible, exposing raw keys in a web dashboard creates an extremely high-severity secret-exposure path and trains users into unsafe handling of wallet credentials.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill encourages users to start automated live trading and explains validation and operation, but omits a clear warning that autonomous execution can rapidly incur losses, execute unintended trades, or consume funds under volatile market conditions. In a high-risk speculative trading context, this omission is security-relevant because it can lead users to enable financially dangerous automation without informed consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly states that the bot can continue trading after sign-out or browser closure, but does not prominently warn about the risk of unattended autonomous trading. This is dangerous because users may wrongly assume signing out stops activity, leading to continued execution, unexpected losses, and delayed response if market conditions or configuration errors cause harmful trades.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.