Back to skill

Security audit

Finance Analysis

Security checks across malware telemetry and agentic risk

Overview

This finance skill is not malicious, but its valuation and risk commands can present fixed sample numbers as if they were real stock-specific analysis.

Review before installing. The code does not show malware behavior, but do not rely on its valuation or risk output for investment decisions unless the publisher clearly labels it as sample mode or replaces it with calculations from current, validated financial data. If you run it, use a limited Tushare token and a virtual environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The valuation and risk commands present hard-coded example numbers while implying they are analyses of the user-supplied stock code. This can mislead users into making financial decisions based on fabricated outputs, which is an integrity issue especially dangerous in a finance tool where users expect stock-specific results.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.