Security audit
Superior Trade Hyperliquid
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed Superior Trade/Hyperliquid trading assistant that can affect real funds, but its authority is clearly tied to its stated trading purpose and includes user-confirmation safeguards for live trading and deposits.
Install only if you intend to let an agent interact with Superior Trade. Treat the API key like a financial credential: it cannot withdraw funds per the artifact, but it can start real trading deployments, close positions through deployment operations, and deposit supported Arbitrum USDC into Hyperliquid. Review each live deployment, deposit, transfer, stop, exit, and delete action before confirming.
SkillSpector
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
62/62 vendors flagged this skill as clean.
