Back to skill

Security audit

Emq

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent for using EMQ CLI, but it gives authenticated portfolio and order commands without enough safeguards for actions that can change account or financial state.

Install only if you trust the emq-cli package and intend to let an agent use an authenticated EMQ account. Use demo or least-privilege credentials where possible, start with read-only market/quota commands, and require the agent to show the exact portfolio, order, or raw command and get explicit approval before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This markdown file includes commands to create portfolios and submit single and batch orders, which can affect user funds or account state. The examples provide no warning that these actions may place real trades or modify live portfolio data, which is a safety-critical omission for markdown content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.