Decker + Hyperliquid

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Hyperliquid trading helper for Decker; it can guide real trades, but the artifacts are instruction-only and include confirmation and safety guidance.

Install only if you intentionally want Decker-assisted Hyperliquid trading. Use a dedicated API wallet with limited funds, do not paste private keys into chat, verify Decker before storing credentials there, and confirm coin, side, size, price, and slippage before any order.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The manifest description includes very broad trigger phrases such as 'DEX', '영구선물', and general Hyperliquid price/position terms, which can cause the skill to activate on ordinary market discussion rather than clear user intent to use Decker. In a trading skill, misrouting is more dangerous than usual because it can steer users into order-execution flows or wallet/key setup guidance when they only wanted information, increasing the chance of unintended financial actions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal