Todays Orders

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is transparent about analyzing one Solana wallet and requires user approval before any on-chain broadcast, though it should be used carefully because it produces transaction guidance.

Install only if you want the agent to analyze a Solana wallet and prepare transaction-oriented daily guidance. Check the wallet address, amount, asset pair, route, slippage, and expected output yourself, and only approve broadcast when you intend an irreversible on-chain transaction.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation while describing activation in broad natural language, which can cause the agent to trigger this high-impact blockchain workflow without sufficiently explicit user intent. Because the skill can read a Solana wallet and approve or preview onchain orders, accidental or prompt-manipulated activation could expose financial data, generate unauthorized trade recommendations, or initiate risky transaction flows.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal