Sales Crypto Sentiment Agent

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed crypto market analysis prompt that can produce speculative trading-style signals, but it does not show hidden execution, credential theft, autonomous trading, or destructive behavior.

Install only if you want speculative crypto market analysis. Do not treat its signals as investment advice, verify market data independently, do not share wallet private keys or authorize trades through it, and check whether your OpenClaw client will install the declared curl and clawhub dependencies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad, generic, and closely aligned with normal user discussion about crypto markets, which increases the chance this skill is invoked unintentionally. In a financial-analysis context, accidental activation is more dangerous because users may receive trading signals or market guidance without explicitly requesting this specific skill, creating confusion and potentially influencing financial decisions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill generates structured trading signals with entries, stop losses, and take profits, but it does not present a prominent upfront warning that such outputs are speculative and can materially affect financial decisions. Although the text says it does not give financial advice, that disclaimer is weaker than an explicit risk warning and may not sufficiently prevent user overreliance on potentially inaccurate or incomplete analysis.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal