Back to skill

Security audit

Silverback Defi

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed DeFi API helper that charges small USDC payments per call, with no hidden code or persistence found.

Install only if you are comfortable with DeFi tooling and wallet-based x402 payments. Use a limited-balance wallet, confirm each 402 charge before paying, never provide seed phrases or private keys, and independently verify any swap or Permit2 signing request. Treat the optional MCP npm package as separate executable software before installing it globally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill prominently advertises paid x402 endpoints but does not clearly warn in the user-facing description that invoking those endpoints will spend USDC from the agent's wallet. This can cause unintended financial loss if users or higher-level agents treat the skill like a normal read-only API and trigger calls without realizing each request authorizes a micropayment.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.