Back to skill

Security audit

Crypto Research Team — Agent Configuration Bundle

Security checks across malware telemetry and agentic risk

Overview

The skill mostly behaves like a research assistant, but its roles are broader and more privileged than its crypto-research description suggests.

Review this skill before installing if you expected a narrow crypto brief generator. It can perform broad web research, write files, store memory, publish events, create schedules, and invoke MCP tools; install only if those capabilities are acceptable and you can constrain outputs, scheduling, and tool access in your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

High
Confidence
89% confidence
Finding
The skill presents itself as a crypto research team, but one role is authorized to perform broad business-opportunity scouting across unrelated domains. This scope mismatch can cause the agent to be invoked or trusted for crypto-only work while actually performing materially different data collection and synthesis tasks, increasing the risk of unintended actions and misuse of granted tools.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The documented workflow implies a bounded crypto-data pipeline, but the included role set supports unrelated business research activity. This inconsistency weakens operator understanding of what the team may do in practice, making overbroad delegation and unsafe invocation more likely.

Vague Triggers

Medium
Confidence
76% confidence
Finding
The skill description is high-level and does not specify when it should be activated or what requests are out of scope. Ambiguous invocation boundaries can cause the skill to be selected for inappropriate tasks, especially given the presence of multiple roles with research and publishing capabilities.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
Multiple roles have file_write capability, but the description does not warn users that the skill can create or modify files as part of its operation. Missing disclosure around state-changing capabilities can lead users to invoke the skill assuming it is read-only research, creating integrity and audit risks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.