Portfolio

Security checks across malware telemetry and agentic risk

Overview

This is a local portfolio-tracking skill that clearly stores investment records on the user's machine and shows no evidence of hidden network access, credential use, or destructive behavior.

Install only if you are comfortable storing portfolio holdings and transaction history in plaintext under ~/.portfolio. Protect that directory on shared or backed-up systems, keep backups if the records matter, and verify any rebalance or performance output before making real financial decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill advertises local JSON storage in `~/.portfolio/` and examples imply persistent file creation/modification, yet no permissions are declared. This creates a capability/consent mismatch: an agent or user may invoke a seemingly low-privilege finance skill without being warned that it writes to disk and may access environment-derived paths such as the home directory.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal