Hyperscaled Funded Account

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Hyperscaled trading assistant, but it deserves Review because it can affect trades and account state while using broad triggers and incomplete confirmation boundaries.

Install only if you intentionally want an agent to manage Hyperscaled trading workflows. Before use, require explicit confirmation for any trade, cancel-all, funded-account purchase, KYC start, or config update, and do not paste private keys into chat or command arguments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises a very broad set of trigger keywords such as trade, order, balance, status, and position, which are common terms that can appear in unrelated conversations. In a skill that can inspect accounts, alter configuration, and initiate trade workflows, accidental invocation increases the chance of unintended sensitive actions or confusing the agent into using this capability when the user did not explicitly request Hyperscaled operations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal