stock-hot-zh-aisa

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed AISA-backed market scanner for hot stocks and crypto, with no evidence of hidden local access, persistence, or destructive behavior.

Install this only if you intend to use AISA for live stock and crypto market summaries. Use a dedicated AISA API key, keep AISA_BASE_URL unset or set only to the trusted endpoint, and treat the output as informational rather than financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger language is broad enough to match many generic market-related requests, which can cause the agent to invoke this skill outside a narrowly intended scope. Over-broad routing increases the chance of unnecessary API-key-backed execution, irrelevant data access, or unreviewed downstream code paths being used when a simpler response would suffice.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal