market_test_price

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed OKX token-price helper that uses OKX credentials only to sign the expected price API request.

Use this only with an OKX API key you are comfortable using for market-data requests, keep the secret and passphrase out of chats and logs, and remember that queried token addresses are sent to OKX.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill declares required credentials and uses code that accesses environment variables and makes outbound network requests, but the metadata only specifies allowed tools and does not clearly declare these sensitive capabilities as permissions. This creates a transparency and governance gap: an agent or reviewer may underestimate that the skill can access secrets and transmit authenticated requests to an external service.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal