Crypto Sentiment Monitor

Security checks across malware telemetry and agentic risk

Overview

This is a lightweight crypto sentiment guidance skill with no bundled executable code, credential collection, persistence, or destructive behavior.

This appears safe to install as a guidance skill, but users should treat its examples as templates: verify any xreach tool and any local analyze_sentiment.py script before running them, and do not provide wallet credentials or private keys because the reviewed skill does not require them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains very broad terms such as "crypto," "sentiment," and short high-frequency words like "FOMO" and "FUD," which can cause the skill to activate in many unrelated conversations. This increases the chance of unintended invocation, unnecessary data access/tool use, and cross-context interference, especially because the skill is designed to aggregate external sources and market-related signals.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal