Back to skill

Security audit

Coil Board

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed market-data research integration that contacts Coil endpoints and optionally uses x402 payment, with no hidden local access, persistence, or trading execution found.

Before installing, treat the outputs as market research rather than trading instructions. If you enable the remote MCP server or paid x402 endpoints, understand that your agent may send requests to Coil and, with a separate payment-capable client, spend small per-read amounts. Do not pair it with broker tools unless you have explicit trading limits and review controls in place.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Tp4

High
Category
MCP Tool Poisoning
Confidence
79% confidence
Finding
A description-behavior mismatch can mislead operators and downstream agents about what data is actually being fetched, whether payment occurs, and whether outputs are paid/live versus free/delayed. In an automated trading or financial-research context, that can cause incorrect trust decisions, stale-data use, unexpected data exposure, or business-logic failures because the skill does not do what it claims.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.