RHO Signals — Live Crypto TA Engine

Security checks across malware telemetry and agentic risk

Overview

This is a simple crypto signal instruction skill with disclosed market-data and future API/payment notes, and no evidence of hidden execution or data access.

Install only if you are comfortable using a crypto market-analysis skill. Treat its buy/sell-style scores as informational, not financial advice. Before using any future live endpoint or x402 payment flow, confirm the price, destination service, and what request data will be sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises a live external HTTP endpoint and micropayment-based access but does not clearly warn users that using it may trigger network requests to a third-party service and incur charges. In an agent setting, this can lead to unexpected outbound data sharing, unreviewed interaction with an untrusted endpoint, and unintended paid transactions if the agent or user follows the documented usage blindly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal