东方财富日内行情 dfcf-stock-intraday

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it fetches public Eastmoney intraday stock or index data and formats it for the user.

Before installing, understand that stock or index identifiers you ask about may be sent to Eastmoney through an HTTPS request. Verify the ticker or secid and treat returned prices as informational, especially because the broad trigger wording may invoke this skill for some general intraday or real-time market questions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill mandates use for a broad set of common market-data queries, which can cause the agent to invoke this external-data skill even when the user did not specifically request Eastmoney data or when another safer/more appropriate source or internal capability would suffice. Over-broad mandatory routing increases the attack surface for prompt/skill hijacking and can lead to unintended external requests, data provenance issues, and reduced user control over tool selection.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal