Back to skill

Security audit

US Stock Market NYSE NASDAQ DOW

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward stock-market data connector, with ordinary caution needed around its external gateway package and API key handling.

Install only if you trust the OneKey Gateway package and DeepNLP agent router. Use a dedicated or revocable API key, avoid the verbose curl example in shared terminals or CI logs, and only send ticker symbols you are comfortable disclosing to the external service.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.