Back to skill

Security audit

流动性管理工具

Security checks across malware telemetry and agentic risk

Overview

This skill is for Uniswap liquidity actions, but its instructions are too broad and mismatched for value-bearing blockchain operations.

Review carefully before installing. Only use this with a wallet setup that requires explicit signing, verify every token address, pool, position ID, amount, network, gas estimate, and slippage setting yourself, and do not allow broad command or file access unless the publisher narrows the scope and removes the unrelated template content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The documentation advertises unrelated premium features such as high-resolution output, style presets, and model fine-tuning, which are inconsistent with a Uniswap liquidity-management skill. This creates deceptive scope, undermines user trust, and can conceal the skill's real behavior or origin, increasing the chance that users invoke it inappropriately or miss genuine transaction risks.

Intent-Code Divergence

Low
Confidence
88% confidence
Finding
The core-function statement is nonsensical and does not clearly describe what the skill does, making activation criteria and expected behavior ambiguous. For a blockchain transaction skill, unclear descriptions are dangerous because users may trigger actions without understanding that wallet-affecting operations could follow.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill expands its described capabilities into generic file handling, API integration, command execution, and information retrieval, which goes well beyond the declared liquidity-management purpose. Combined with the declared read/exec/write tools, this broad scope materially increases attack surface and could enable unauthorized local actions or data access under the cover of a finance workflow.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation description is overly broad, indicating the skill should be used whenever the user needs 'tool-related functions,' which fails to meaningfully constrain invocation. In a financial skill capable of facilitating irreversible on-chain operations, ambiguous routing increases the risk of accidental activation and unintended transaction preparation.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The core-function summary uses vague trigger wording and does not clearly delimit when the skill should run or what safety checks apply. That ambiguity is more dangerous in a DeFi context because even preparatory actions like approvals, pool selection, or transaction generation can expose users to loss if launched under the wrong intent.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill description for adding/removing liquidity and collecting fees lacks a clear warning that blockchain approvals and transactions may be irreversible, value-bearing, and subject to slippage, MEV, and wrong-pool selection. In DeFi, omission of these warnings can directly contribute to users approving or executing harmful transactions without informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.