Coin Identifier

Security checks across malware telemetry and agentic risk

Overview

This is a coin-photo identification skill with optional local notes, and its artifacts disclose the storage location and require user approval before writing files.

Safe to install for coin identification. During first setup, choose narrow activation if you only want help on explicit coin-ID requests, and decline local storage unless you want preferences and saved identifications kept in ~/coin-identifier/.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The setup instructs the skill to clarify and potentially broaden when it should activate in future conversations, including triggering whenever coins, mint marks, or unidentified collection pieces are mentioned and possibly jumping in proactively. In an agent setting, overly broad activation criteria can cause the skill to engage outside the user's intent, leading to scope creep, unnecessary data collection, or inappropriate persistence of preferences across unrelated conversations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal