Back to skill

Security audit

Crypto Search Advisor

Security checks across malware telemetry and agentic risk

Overview

This skill does not appear to steal data or execute trades, but it should be reviewed because it gives actionable crypto trading guidance while presenting itself as informational.

Install only if you intentionally want a crypto chart/search analysis assistant. Do not treat its outputs as investment advice or let it drive automated trading; verify prices and risks independently. Avoid uploading screenshots that show balances, account identifiers, wallet details, or other private financial information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The spec materially expands the skill from passive screenshot/search analysis into a '交易决策系统' that generates structured trading guidance such as directional bias, target zones, risk-reward estimates, and action-oriented recommendations. Even with disclaimers, this creates a system that can influence financial decisions in a high-risk domain, increasing the chance of unsafe or non-compliant behavior.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The document states that outputs are '仅供参考不做交易决策' while simultaneously standardizing fields that function as trading signals and decision support. This contradiction is dangerous because disclaimers do not neutralize operationally actionable content, and users may rely on the structured recommendations as investment advice.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
Although the boundary says direct trading is unsupported, the examples include concrete advice such as immediate position reduction, switching assets, or exiting. In a crypto context, those instructions are effectively trading recommendations and can prompt users to take immediate financial actions under perceived urgency.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The function emits interpretive market statements such as '短期动能转弱', '中期趋势向下', and '放量下跌,筹码出逃', which are directional or advisory in nature despite the module claiming it only reports non-directional structural risk. In a crypto decision-support skill, this mismatch can mislead users about the scope and reliability of the output and can function as de facto financial guidance.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The cold-start templates promise supplementary ETF flow, on-chain flow, social heat, unlock schedules, and other external-context analysis, which exceeds a screenshot-only analysis claim. This is dangerous because it can create false user expectations about data provenance and analytical coverage, especially in a high-risk financial context where users may rely on implied external intelligence that is not actually available or verified.

Intent-Code Divergence

High
Confidence
94% confidence
Finding
The top-level documentation asserts strict prohibitions on direction prediction, certainty, searching, and reasoning, but the codebase contains logic and text that infer trend weakness/strength and interpret market conditions. Such policy/behavior divergence is a security-relevant integrity issue because it undermines trust boundaries and safety guarantees presented to users in a financial-analysis skill.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The file contains reconciliation logic using ETF netflow, exchange netflow, and fear-greed sentiment, while the generated output claims it excludes macro, funds, and sentiment judgments. Even if not currently invoked on the main path, latent contradictory capability is risky because future integration could silently bypass user expectations and produce analyses based on undisclosed external factors.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The example explicitly provides directional trading and position guidance such as '建议轻仓观察,等待放量突破后加仓' without any accompanying warning that the output is not investment advice and that crypto markets carry substantial loss risk. In a crypto-analysis skill, users may reasonably rely on example outputs as endorsed behavior, increasing the chance of financial harm or inappropriate automation of trading decisions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The stablecoin example includes strategy guidance ('可作为过渡性资金载体') that can be interpreted as a recommendation to use USDT in portfolio or transaction flow decisions, but it lacks any caution about depeg risk, counterparty risk, liquidity stress, or general financial risk. Because stablecoins are often perceived as low-risk, omission of warnings may create misplaced trust and encourage unsafe financial behavior.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The README describes activation in very broad terms such as sending any exchange screenshot or asking about any token, without clear gating conditions, scope limits, or user-consent boundaries. In an agent ecosystem, this can cause the skill to trigger on common financial or image-sharing behavior unexpectedly, leading to unsolicited networked analysis of sensitive screenshots and increasing the chance of misuse or overreach.

Vague Triggers

High
Confidence
95% confidence
Finding
The activation rule requires the skill flow for any mention of cryptocurrency terms, which is excessively broad and can hijack unrelated conversations that merely reference crypto in passing. This creates unnecessary tool invocation and scope capture, increasing the chance of unintended data processing, misleading responses, or policy bypass of the host agent’s normal routing and safety logic.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The welcome-trigger examples include vague greetings like '你好' or '能做什么', which can cause the crypto skill to activate even when the user has not expressed any cryptocurrency-related intent. In a multi-skill environment, this can lead to accidental invocation, confusing handoffs, and over-collection or over-processing of user inputs under the wrong skill context.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.