Back to skill

Security audit

Defi Intelligence Skill

Security checks across malware telemetry and agentic risk

Overview

The skill clearly discloses paid DeFi data requests and optional irreversible on-chain actions, with no artifact evidence of hidden or malicious behavior.

Install only if you trust the Spraay gateway and understand that wallet addresses and portfolio data leave your environment and that some calls cost USDC. Use a limited test wallet, review every parameter carefully, and require explicit approval before any swap or contract write.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.