n0ir DeFi Yield Scout

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward DeFi yield comparison tool, with financial-estimate caveats users should keep in mind.

Install only if you are comfortable with a local Python script making HTTPS requests to DeFiLlama and writing a short-lived temp cache. Verify APY, protocol risk, bridge/gas cost, and smart-contract risk independently before making any DeFi allocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The breakeven command presents prescriptive labels like GO, MAYBE, and NO-GO based on a highly simplified heuristic, but it does not warn users that the output is only an estimate and not financial advice. In a DeFi context, users may over-trust these recommendations and make real fund allocation decisions without understanding omitted risks such as smart contract risk, slippage, bridge risk, withdrawal limits, reward volatility, or stale API data.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal