Back to skill

Security audit

gate-info-marketoverview

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only crypto market overview helper with minor routing ambiguity but no evidence of unsafe behavior.

Safe to install if you trust the Gate MCP server. Treat the output as informational market context, not investment advice, and use the more specialized Gate skills for coin-specific, technical, risk, or deep research requests.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The scenario document tells the agent to route single-coin queries to gate-info-coinanalysis, while the skill metadata says such queries should go to gate-info-research. This inconsistency can cause misrouting, leading the agent to use a narrower or unintended skill path and potentially omit required analysis dimensions or safeguards.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases are generic and overlap with common requests, which increases the chance this skill is invoked when the user intent is broader, ambiguous, or actually requires coin-specific or multi-dimensional analysis. Incorrect triggering can produce incomplete answers and bypass the more appropriate skill selection logic described in the metadata.

Static analysis

No suspicious patterns detected.