同花顺股票接口

Security checks across malware telemetry and agentic risk

Overview

This is a read-only stock-market analysis skill with some routing and dependency cautions, but no evidence of hidden, destructive, or credential-seeking behavior.

Install this only if you trust the thsdk package and the THS/Wencai data provider. Prefer a virtual environment or pinned dependency for supply-chain control, and avoid sending confidential trading strategies, private watchlists, or personal financial details in natural-language screening queries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The activation description contains many broad trigger phrases and an explicit 'must use this skill' rule, which can cause the orchestrator to invoke the skill for loosely related financial conversations. This increases the chance of unnecessary tool usage, incorrect routing, and unintended external data access, especially when the user did not clearly request advanced market analysis.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill metadata and guidance strongly assume Chinese-only interaction and do not offer language negotiation, which can cause the system to respond in an unintended language or degrade user understanding. While this is not a direct code-execution risk, it is a real safety and usability issue because it can mislead users, produce incorrect interpretation of financial information, and reduce informed consent around tool use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal