Market Snapshot

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward token market-data lookup that uses a disclosed external API and does not request wallets, secrets, installs, local files, or privileged access.

Install this only if you are comfortable with token symbols, names, or mint addresses being sent to Vecstack for lookup. Avoid putting private or unrelated information in market queries, and treat returned market data as informational rather than trading advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation guidance includes broad triggers like 'prices', 'market snapshots', 'token metadata', or 'what is X doing', which can match casual conversation and cause the skill to run when the user did not clearly request an external market lookup. This increases the chance of unintended network calls and tool use, especially in agentic settings where over-eager invocation can leak conversational context into requests or create noisy/incorrect behavior.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal