Back to skill

Security audit

money-management

Security checks across malware telemetry and agentic risk

Overview

This skill provides disclosed trading risk-management guidance and does not request tools, account access, persistence, or code execution.

Before installing, understand that this skill can influence trading risk decisions and is written mostly in Chinese. Use it as educational risk-management support, not as personalized financial advice, and ask the agent to respond in your preferred language if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill metadata and content are written primarily in Chinese and strongly frame activation and usage in that language, without any indication that the assistant should adapt to the user's language preference. In a multi-skill system, this can cause unwanted language switching, reduce user comprehension, and create safety/compliance failures if critical financial risk guidance is delivered in a language the user did not request or fully understand.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.