Back to skill

Security audit

📊 Crypto Arbitrage Monitor - 套利信号监控

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed crypto funding-rate monitor that gives trading signals, but it does not execute trades, request credentials, or persist data.

Install only if you want an agent to produce crypto arbitrage monitoring reports and trading-signal style analysis. Treat the results as research, not financial advice; confirm current market data yourself before acting, and avoid using it for casual definitions, translation, or general crypto discussion unless you explicitly want the monitor invoked.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes generic finance terms such as "资金费率", "arbitrage", and "套利机会", which can match ordinary educational, market-commentary, or translation requests rather than an explicit request to run this skill. That can cause unintended activation and produce trading-oriented guidance in contexts where the user did not ask for actionable monitoring, increasing the chance of unsafe or irrelevant responses.

Vague Triggers

Low
Confidence
84% confidence
Finding
The invocation conditions enumerate positive examples but provide no scope limits, exclusions, or confirmation step before gathering data and producing buy/watch/risk signals. In a financial trading context, unclear boundaries make accidental invocation more likely and can lead the agent to present quasi-advisory output when the user may only want background information.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill description and output format are written to produce Chinese-language content without offering a language-selection path. This can mis-handle users interacting in other languages, increasing misunderstanding of trading signals and risk disclosures in a high-stakes financial context.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.