Binance Trading Signal

Security checks across malware telemetry and agentic risk

Overview

This is a read-only trading-signal reference skill, but users should treat its output as market data rather than financial advice.

Install only if you want the agent to fetch Binance Web3 smart-money signal data. Verify the publisher and endpoint independently, and treat all signals as informational, volatile, and possibly wrong or manipulated; do not allow the agent to make trading decisions without explicit user review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill is explicitly framed for users 'looking for investment opportunities,' which is an overly broad trigger for a high-risk financial domain. This can cause the agent to invoke speculative trading guidance in situations where the user may only want general market information, increasing the chance of unsuitable financial suggestions without adequate caution.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The description promotes the skill as a source of 'valuable references for potential trades' without any balancing risk disclosure. In a financial context, this can mislead users into treating noisy or promotional on-chain signals as actionable investment advice, especially for volatile assets like Pump.fun tokens.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal