Back to skill

Security audit

Token Layer Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a crypto token lookup aid, but it asks for broader write and command execution authority than its read-focused purpose clearly justifies.

Review this before installing if you expect a read-only token lookup skill. It may be acceptable for users who knowingly want an exec-enabled crypto data helper, but the publisher should narrow the declared permissions, remove generic routing language, and clearly define what files may be written or exported.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a read-oriented token lookup tool, but it declares write and exec permissions and states that core operations support create/query/export. This mismatch can mislead an agent into granting broader authority than users expect, increasing the chance of unintended file modification or arbitrary command execution under a benign-looking data-query label.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The documentation says the free edition does not support certain advanced features, yet later advertises a verify command. Such contradictory capability descriptions can cause agents or users to invoke operations they did not intend to permit, undermining trust boundaries and making it harder to reason about what the skill may execute.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation text uses broad triggers such as generic data analysis, reporting, statistics, and visualization, which extend far beyond a narrow cross-chain token query tool. Overbroad routing language can cause the skill to be selected in unrelated contexts, exposing exec-enabled functionality more often than necessary and increasing the attack surface for prompt or tool misuse.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The capability coverage section lists a long set of loosely constrained keywords, including generic terms like data analysis, reporting, and automation workflow. In an agent ecosystem, this acts like overbroad prompt routing and can trigger an exec-capable skill in contexts unrelated to its intended domain, raising the risk of unnecessary command execution and privilege exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.