celo-defi

Security checks across malware telemetry and agentic risk

Overview

This skill is a Celo DeFi reference guide with visible transaction examples, not an installer or hidden executable.

Treat this as reference material, not audited production code. Before using it with real funds, verify contract addresses, test on Alfajores or simulation first, use bounded slippage and exact allowances, show explicit wallet confirmations, and explain borrow, liquidation, approval, and irreversible-transaction risks to users.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill includes ready-to-use examples that submit live wallet transactions for swaps, borrowing, supplying, and ERC-20 approvals, but it does not clearly warn that these actions can move funds, grant spending authority, incur slippage, or create debt. In an agent-skill context, users may copy or invoke snippets with limited review, making omission of explicit wallet-impact and financial-risk warnings materially unsafe.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal