Back to skill

Security audit

Methodalgo Market Intel Explorer

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent read-only crypto market data helper that installs a disclosed CLI and uses a MethodAlgo API key for market intelligence requests.

Install only if you are comfortable using a global npm CLI and sending market queries, symbols, search terms, and request parameters to MethodAlgo and, for Binance commands, Binance public endpoints. Do not include secrets or proprietary trading strategy details in prompts or search strings; keep the MethodAlgo API key scoped and rotate it if exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
95% confidence
Finding
The skill routes user requests to external MethodAlgo and Binance services, including search terms, symbols, and market-interest context, but the description does not clearly disclose this data flow. This is a real privacy/transparency issue because users or upstream agents may unknowingly send sensitive research interests or proprietary trading queries to third-party services.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.