Back to skill

Security audit

加密货币监控与告警

Security checks across malware telemetry and agentic risk

Overview

This appears to be a crypto market-monitoring skill with advice-like report sections that users should treat as informational, not as trading guidance.

Install only if you want crypto market monitoring and heuristic token-risk analysis. Do not rely on generated 'operation' or trading suggestions as financial advice, and confirm before creating alerts or acting on any risk score.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The daily report template includes an '操作建议' section, which expands the skill from passive market monitoring into actionable investment guidance. That creates a scope violation against the manifest and can cause users to rely on generated financial recommendations that were not intended, reviewed, or safety-constrained.

Description-Behavior Mismatch

Medium
Confidence
81% confidence
Finding
The rug-pull detection and holder/contract assessment logic goes beyond the declared scope of basic price monitoring and alerts. While not directly a classic security flaw, it introduces unadvertised analytical behavior that may be treated by users as authoritative risk screening, increasing mismatch between declared and actual capability.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger phrases are broad enough that ordinary market-related conversation could invoke the skill unintentionally. Misfires can cause unsolicited network access, unwanted alert creation, or confusing outputs in contexts where the user did not intend to activate a crypto-monitoring workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.