Crypto 4h Trade Brief

Security checks across malware telemetry and agentic risk

Overview

This skill transparently runs a disclosed local market-data analyzer and gives manual crypto trading templates, with no evidence of hidden access or automatic trading.

Install only if you want a Chinese-language crypto trading brief that may execute the referenced local analyzer script. Review that dependency first, verify prices independently, and treat the generated OKX leverage/grid parameters as decision support, not financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The manifest description includes broad trigger phrases such as '每4小时分析', '给欧易手填参数', and '合约+网格参数建议', which can cause the skill to activate for ordinary market-discussion requests without clear user intent to invoke automated trading guidance. In this context, overbroad matching is more dangerous because the skill produces actionable contract and grid trading parameters, so accidental invocation could escalate a casual conversation into leveraged financial advice.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill mandates Chinese output regardless of user preference, which overrides user choice and can reduce comprehension for users expecting another language. In a high-risk trading context, this becomes more concerning because misunderstanding entry, stop-loss, or termination conditions could lead to incorrect execution of financial trades.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal