Back to skill

Security audit

Combined Alpha

Security checks across malware telemetry and agentic risk

Overview

This skill is a paid crypto trading-signal connector that clearly discloses its wallet requirement and per-call pricing, with no hidden code or persistence found.

Before installing, use a dedicated low-balance wallet rather than a primary wallet, understand that calls are paid, and avoid invoking the skill automatically in loops or high-frequency workflows unless you have explicit spend controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs the agent to use an on-chain private key from the environment to make an x402-authenticated paid request, but it does not present any explicit warning about charges, wallet usage, or privacy implications. This is risky because an agent or user could unknowingly authorize billable requests and expose a sensitive signing credential to a third-party payment flow without informed consent or clear spend controls.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal