Back to skill

Security audit

Arb Engine

Security checks across malware telemetry and agentic risk

Overview

This crypto-arbitrage skill is not clearly malicious, but it asks for command execution and describes automated trading without enough scoping or user-control safeguards.

Install only if you are comfortable giving this skill command-execution capability in a cryptocurrency context. Keep exchange API keys read-only or minimally scoped, avoid enabling withdrawal/trading permissions unless you explicitly intend that, and require manual confirmation for any order placement, package installation, file modification, or shell command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill claims that risky external-code behavior and sensitive-data leakage paths were removed, yet elsewhere it still documents command execution, file operations, and API/network use. This creates a misleading trust signal that can cause users or agents to lower their guard around capabilities that still carry system and secret-exposure risk.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill is presented as a focused cryptocurrency arbitrage engine, but later expands into generic file-processing and command-execution workflows. This scope drift increases the attack surface because an agent may invoke broader local-system actions under the cover of a domain-specific finance skill.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation description is overly broad, causing the skill to be eligible for many loosely related user requests. In an agent environment, ambiguous activation can trigger finance-related analysis, API use, or execution paths in situations where the user did not clearly request high-risk behavior.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown advertises automated trading and command execution capabilities without clear warnings, consent requirements, or operational safeguards. In the context of a crypto-arbitrage skill with exec access, this is especially dangerous because mistakes or abuse can cause real financial loss and unintended system changes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.