Hourly Momentum Trader

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed crypto betting-analysis skill, but users should treat its recommendations as risky speculation rather than reliable trading advice.

Install only if you specifically want speculative crypto or prediction-market signal analysis. Do not treat its BET UP or similar outputs as financial advice, and avoid connecting it to any real-money workflow unless you add your own risk limits, confirmation steps, and loss warnings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is overly broad and can cause the agent to invoke this trading skill in loosely related contexts without clear user intent. In a financial and betting context, accidental invocation increases the chance of unsolicited trading guidance being surfaced, which can mislead users into acting on risky market signals.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill gives concrete live betting and payout-optimization guidance, including edge formulas, bet conditions, and counter-consensus wagering strategies, without any warning about financial loss, model uncertainty, or the speculative nature of prediction markets. In this context, the omission is dangerous because it can encourage users to place real-money trades based on simplistic heuristics presented with unwarranted confidence.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal