Pinescript mastery

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Pine Script helper with no executable install behavior, but trading outputs should be independently tested before any real-money use.

Safe to install as a Pine Script coding aid. Treat generated strategies as drafts: review the code, test in TradingView with realistic fees and slippage, validate out-of-sample, and avoid connecting alerts or generated logic to live trading without independent review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest says to trigger on "any request involving TradingView indicator or strategy development" and even when a user merely describes a trading idea without mentioning Pine Script. That activation condition is broad and lacks exclusion criteria, so it could capture ordinary trading-strategy discussions or analysis requests that do not actually intend Pine Script code generation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal