Back to skill

Security audit

Whale Scanner

Security checks across malware telemetry and agentic risk

Overview

This skill is a small external API wrapper for whale-flow signals, with a disclosed premium-payment prompt but no automatic payment, credential access, persistence, or local data access.

Before installing, understand that ticker requests are sent to an external API and premium results may ask you to send SOL to a listed wallet or pricing page. Only pay if you trust the publisher and can independently verify the service and payment destination.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
This is a mismatch because the description only says the skill performs real-time institutional transaction monitoring, but the code also contains a monetization/payment solicitation path that asks the user to send 0.005 SOL to a specific wallet when the upstream service returns HTTP 402. That payment-request behavior is not disclosed in the description. Additionally, the code's actual behavior is simply forwarding requests to an external whale API and relaying its response, which is narrower and less transparent than the declared purpose.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.