Back to skill

Security audit

Gekko

Security checks across malware telemetry and agentic risk

Overview

This is a read-only DeFi analysis skill that clearly uses Gekko's remote API, with privacy and financial-risk cautions but no evidence of hidden execution, credential collection, persistence, or fund movement.

Install only if you are comfortable sending DeFi questions and token or portfolio-related inputs to Gekko's remote service. Do not enter seed phrases, private keys, wallet credentials, API keys, confidential trading plans, or nonpublic strategy details, and verify any yield or allocation recommendation before moving funds.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README advertises a broad, open-ended chat capability about markets, strategies, tokens, and yields without clearly constraining allowed topics, actions, or safety boundaries. In an agentic DeFi context, ambiguous scope increases the risk that users or downstream orchestrators treat the skill as a general-purpose financial or operational assistant, enabling prompt-injection abuse, unsafe financial guidance, or unintended action selection beyond the intended read-only portfolio-analysis use case.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill exposes a generic `chat` capability that accepts arbitrary user messages and forwards them to a remote third-party agent endpoint without any documented scope limits, safety boundaries, or trigger constraints. In a DeFi portfolio-management context, this increases the chance of prompt-injection-style misuse, sensitive data disclosure, and unsafe financial guidance being elicited through an unconstrained interface.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages users to submit portfolio, token, and market-analysis queries to `https://gekkoterminal.ai/api/a2a?agent=gekko` but does not clearly warn that this data is sent to a third-party service. In a financial/DeFi setting, queries can reveal holdings, strategy, wallet-associated interests, or trading intent, creating privacy and surveillance risks even if no direct exploit occurs.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.