Use Usdc

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed USDC helper for balances, transfers, approvals, and verification, but users must handle wallet keys and transaction confirmations carefully.

Install only if you are comfortable managing wallet keys and signing blockchain transactions. Prefer test wallets, small amounts, and wallet-mediated or hardware signing when possible; never paste private keys into chat, logs, source control, or shared environments. Verify the chain, USDC contract or mint, recipient, amount, and spender before every transfer or approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes generic phrases like 'check balance' that can match requests outside the USDC-specific scope, causing the agent to invoke this skill in the wrong context. In a financial skill that can guide token transfers and approvals, overbroad routing increases the chance of confusing assets, chains, or transaction semantics and may lead to unsafe or incorrect actions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal