Back to skill

Security audit

kronos-signals-api

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent paid crypto-data API guide, but it enables automatic real-USDC payments without clear user approval or enforced spend controls.

Install only if you are comfortable connecting a wallet-enabled payment flow to this API. Configure the calling agent to require explicit approval for paid calls, prefer the free health and stats endpoints first, and set a hard daily or per-task USDC limit before allowing repeated cycles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This skill explicitly instructs the agent to invoke paid endpoints that trigger real USDC micropayments, but it does not require a clear user-facing confirmation immediately before spending funds. In an agent setting, that can cause unintended real-money transactions from automated tool use, especially because the document emphasizes convenience and batching/cycle recommendations more than consent and spend approval boundaries.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.