OnChain Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for analyzing blockchain transaction data, with no executable code or hidden install behavior.

Install this only if you want help interpreting on-chain wallet, contract, and transaction data. Provide public addresses, transaction hashes, chain, timeframe, and relevant labels only; do not provide private keys, seed phrases, exchange credentials, signing access, or unnecessary financial context. Consider narrowing the trigger phrases if accidental activation would be a concern.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger set is broad enough to match many normal user requests about blockchain investigation, which can cause this skill to activate unexpectedly and override more specific or safer routing choices. In an agent environment, trigger collisions can lead to unintended skill invocation, confused delegation, and expanded exposure to downstream capabilities or data the user did not explicitly target.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal