Back to skill

Security audit

Btcvision Daily Brief

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple Bitcoin briefing template that discloses its external data source and optional channel delivery, with no executable code or hidden behavior found.

Before installing, configure any Telegram, Discord, or Slack destination deliberately and treat the cron example as opt-in automation. Use preview or confirmation in your own workflow if the target channel is public, shared, or sensitive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill advertises sending automated reports to Telegram/Discord/Slack without any explicit user-facing warning that content will be transmitted to external services. In an agent environment, this can lead to unintended outbound disclosure of generated content or contextual data if the user does not realize a third-party destination is involved.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The instruction to send the formatted brief to a Telegram/Discord/Slack channel lacks a user warning or confirmation gate for external transmission. This makes the skill more dangerous because the final step operationalizes outbound messaging, which could result in accidental posting to public or sensitive channels.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.