Back to skill

Security audit

DeFi Due Diligence

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent crypto-token risk checker, but its broad activation wording plus automatic paid x402 wallet flow could cause unintended $2 USDC charges without clear user confirmation.

Install only if you want an external paid token-checking service. Configure your agent or wallet to require explicit confirmation before any x402 payment, and avoid letting the skill auto-run on casual crypto questions or bare token symbols.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger section is broad enough to fire on many generic crypto-investing conversations, including casual questions like whether a token is legit or should be bought. That can cause unintended invocation of an external paid skill, increasing the chance of unnecessary data disclosure, surprise charges, or over-reliance on a third-party verdict in ordinary chats.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.