Back to skill

Security audit

Altcoin Season

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent x402 paid-API helper, but it uses a funded wallet private key for automatic paid requests without sufficiently strong user-control guidance.

Install only if you are comfortable letting the skill authorize paid x402 calls. Use a dedicated wallet with very limited USDC, avoid a primary wallet private key, set spending limits where possible, and require explicit confirmation before paid requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to make an x402-authenticated request using an on-chain wallet private key and notes that payment authorization happens automatically, but it does not present this as a prominent safety warning. This can mislead users into invoking the skill without understanding that they are exposing a funded signing key to an external payment flow and may incur real charges per call.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal