binancesquare

Security checks across malware telemetry and agentic risk

Overview

This skill fetches recent public-style Binance Square posts from a disclosed external endpoint and prints a filtered table, with no evidence of local data access or persistence.

Install only if you are comfortable letting the skill contact the disclosed bmwweb.cc endpoint to retrieve Binance Square-style data. Do not add personal Binance cookies, tokens, or account credentials unless the skill is re-reviewed for that use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The invocation text is broad enough to encourage execution without clear user intent, scope, or confirmation boundaries. For a networked skill, that increases the chance of unintended remote requests, repeated scraping, or use in contexts the user did not explicitly authorize.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal