Back to skill

Security audit

web3-protocol-gtm

Security checks across malware telemetry and agentic risk

Overview

The skill is a markdown-only web3 GTM playbook, but one payment-growth section under-scopes sanctions and AML compliance risk.

Review the compliance posture before installing or using this skill. Treat its token-launch and crypto-payment guidance as educational only; do not use it to serve sanctioned or restricted users, bypass banks, or avoid payment regulations. Use qualified legal review, sanctions screening, AML/KYC controls, geofencing where required, and clear paid-promotion disclosures.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The document explicitly identifies 'users in sanctioned regions' and businesses avoiding banks as target customers for crypto payment rails without any legal/compliance warning, risk framing, or exclusion guidance. In a web3 GTM skill, this can normalize or encourage sanctions evasion and servicing restricted actors, creating material legal, regulatory, and reputational exposure for operators who follow the advice.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.