Back to skill

Security audit

Position Exposure

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed paid trading-signal skill that uses an EVM private key to authorize x402 payments, with no hidden executable behavior found.

Install only if you want the agent to make paid x402 requests. Use a dedicated low-balance wallet, understand that calls can spend USDC on Base mainnet, and require confirmation before repeated or automated use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to make an authenticated paid request using an EVM private key and states that payment authorization is handled automatically, but it does not clearly warn that invoking the skill can spend on-chain funds or involve transmission/use of wallet-derived credentials. In an agent context, this creates a real risk of unintended financial charges and unsafe secret use because users may treat the call as a normal read-only API request.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.