Back to skill

Security audit

gate-info-coincompare

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a crypto comparison guidance skill with a routing-scoping weakness, not a skill that installs code, persists access, or performs hidden actions.

Before installing, be aware that the skill may be invoked by broad comparison wording such as “vs” or “which is better.” Use it only for clearly identified crypto assets, and do not treat its analysis as financial advice or trading authorization.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases include very broad language such as "compare," "vs," "which is better," and "difference," which can match many ordinary user requests outside this skill's intended scope. This can cause the agent to invoke the coin-comparison workflow unexpectedly, increasing the chance of inappropriate routing, unnecessary tool calls, and misleading financial-analysis outputs in unrelated contexts.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger scenario description is underspecified and does not define clear boundaries for when this skill should not run. In an agent environment, ambiguous routing can be exploited or accidentally triggered by loosely related prompts, leading to wrong-skill execution and potentially unsafe or confusing outputs in a finance context.

Static analysis

No suspicious patterns detected.