bitmart wallet skill

Security checks across malware telemetry and agentic risk

Overview

This is a read-only BitMart Web3 data skill; the main privacy consideration is that wallet addresses and token queries may be sent to BitMart APIs.

Install this if you want an agent to use BitMart's public Web3 market and wallet data. Avoid querying wallet addresses you do not want associated with your request to BitMart, and treat swap quotes and market data as informational rather than trade execution or financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is overly broad and maps to common wallet, token-price, market-data, and transaction-history requests without clear scoping boundaries. This increases the chance of over-invocation on sensitive financial queries, causing unnecessary disclosure of wallet activity and expanding the blast radius if the skill is selected when a narrower tool would suffice.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill supports wallet balance, recent transaction, and smart-money address analysis, but the user-facing description does not warn that submitting a wallet address will trigger on-chain activity lookups. In practice, users may provide addresses without understanding that the agent will query and summarize potentially sensitive financial activity, creating privacy and consent risks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal