Web3Tech
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's stated purpose (crypto project research) aligns with its requirements and instructions: it only asks for a single WEB3TECH_API_KEY and contains instruction-only guidance that references only the web3tech MCP tools and internal templates.
This skill appears internally consistent, but it relies on a remote MCP server you must trust. Before installing: verify the Web3Tech provider (review https://web3tech.org, privacy/terms, and reputation); only give the API key the minimal scope needed and rotate/revoke it if you stop using the skill; avoid sending private keys or non-public secrets as part of prompts; monitor API usage for unexpected calls; and be cautious when the agent requests deep developer profiling — validate that only public data is being fetched. If you need higher assurance, request the skill's network endpoints and API specs from the provider or test it in an isolated account/key first.
SkillSpector
SkillSpector findings are pending for this release.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
