Back to skill

Security audit

farmdash trail intelligence

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed read-only DeFi research and planning tool, but users should treat its financial suggestions and affiliate routes carefully.

Before installing, understand that this skill can send public wallet and portfolio-sizing information to FarmDash and may show FarmDash affiliate or referral routes with disclosure. Do not provide private keys, seed phrases, signatures, or wallet write permissions; use its output as research, not financial advice or automatic trading instructions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The manifest advertises a research/ranking skill, but its tools also include personalized rebalancing and capital-routing guidance. That scope expansion can cause an orchestrator or user to treat the skill as advisory or action-adjacent, increasing the chance of unsafe financial recommendations, unintended tool invocation, or routing users toward affiliate-linked actions without clear separation from neutral research.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The top-level description is broad enough to trigger the skill for many DeFi, wallet-analysis, and protocol-event queries without clearly stating when it should or should not be used. In an agentic environment, overly broad invocation language can cause the wrong skill to be selected for sensitive requests, leading to inappropriate financial guidance, privacy-impacting wallet analysis, or cross-skill confusion.

Vague Triggers

Low
Confidence
76% confidence
Finding
The tag set is very broad and spans multiple adjacent domains such as DeFi research, wallet analysis, airdrops, sybil risk, restaking, and MCP. Excessively broad tags increase accidental invocation overlap with other finance or wallet-related skills, which is risky here because the skill handles sensitive topics like portfolio optimization and public wallet assessment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.