Back to skill

Security audit

crypto-research-checklist

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed crypto due-diligence helper that may call a paid external analysis API, with no evidence of hidden persistence, credential access, destructive behavior, or unrelated data use.

Install only if you want an agent to send crypto project queries to Onchain Intelligence and potentially complete a small x402 payment from an agent wallet. For financial discussions, treat the PASS/WATCH/FLAG result as research support, not investment advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The metadata description embeds very broad trigger phrases like 'research this coin', 'is this project legit', and 'should I buy this token', which overlap with common user investment language and can cause the skill to activate in contexts where the user did not explicitly request this specific tool. In an investing context, unintended invocation is risky because it may route users into an automated paid analysis flow and present a simplified PASS/WATCH/FLAG verdict on speculative assets.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger section says to use the skill whenever the user is considering a crypto project and lists highly ambiguous phrases such as 'is this legit?' and 'should I invest?', without requiring explicit consent or clear boundaries. This increases the chance of accidental activation during general financial discussions, which is especially concerning here because the skill can initiate a paid external API workflow and produce authoritative-sounding due-diligence outputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.