Back to skill

Security audit

aimpact-crypto

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed crypto-news reporter that fetches from two listed APIs and can optionally send reports through already configured messaging channels.

Install this if you trust the agent.me.news API sources and want crypto reports from them. If you do not want reports sent outside the chat, do not configure message channels or cron/scheduled tasks for this skill; test manual report generation first and confirm any destination channel before enabling scheduled delivery.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.