Back to skill

Security audit

全球财经早报 Global Market Briefing

Security checks across malware telemetry and agentic risk

Overview

This skill fetches public market/news data and creates a local Markdown briefing, with optional user-configured scheduling that fits its stated purpose.

Before installing, confirm you want reports saved to the Desktop folder shown in the README and only enable the schedule if you want recurring network fetches and file creation. Review or change the output directory if local retention matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Low
Confidence
84% confidence
Finding
The markdown advertises automatic scheduled execution and local archiving, but does not warn users that the skill will write files and can run unattended on a schedule. That omission can cause users to enable persistent background behavior without understanding storage growth, repeated network access, or the operational/security implications of allowing exec-based scheduled runs.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.