Back to skill

Security audit

Apex Composite

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent paid crypto-signal integration, but it asks an agent to use an EVM private key and automatically authorize paid wallet requests without a clear confirmation or spending limit.

Install only if you intend the agent to make paid requests to this service. Use a dedicated wallet with limited USDC on Base, monitor calls and costs, and avoid exposing a primary wallet private key.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly states that payment authorization is handled automatically and requires use of an EVM private key, but it does not clearly warn the user that invoking the skill can spend funds from the connected wallet. In an agent context, this can lead to unintended on-chain charges or repeated paid requests without informed user consent, especially because the workflow is presented as frictionless and automatic.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal