stock-hot-zh

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed market-scanning skill that calls an external AISA API with a user-provided key and does not show hidden local access or persistence.

Install only if you trust the AISA endpoint and are comfortable providing an AISA_API_KEY for external API calls. Expect user prompts about market movers to be sent to that service, and treat the resulting stock or crypto output as informational rather than financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger language is broad enough to match ordinary market-chat requests like 'what's hot' or 'what's moving,' which can cause the skill to be invoked when the user did not clearly request this tool. Unintended invocation increases the chance of unnecessary external API calls, surprising behavior, and use of credentials in contexts where a simpler response would suffice.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal