Binance Web3 Openapi Skill

Security checks across malware telemetry and agentic risk

Overview

This is a read-only Binance Web3 data skill; it can look up public wallet holdings, but it does not show evidence of trading, credential use, persistence, or hidden behavior.

Install only if you are comfortable using Binance Web3 public APIs for crypto research. Treat wallet-address lookups as sensitive: query addresses only when the user clearly asks or has authority, and do not present token audit or smart-money data as financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
78% confidence
Finding
The schema exposes an endpoint that retrieves wallet address holdings/positions but does not warn that this can reveal sensitive financial profiling information about a user or third party. In an agent skill context, absence of disclosure and consent guidance increases the risk of privacy-invasive use, especially because wallet addresses can be tied to transaction history and investment behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal