Back to skill

Security audit

yanji-tech-indicators

Security checks across malware telemetry and agentic risk

Overview

This skill is not destructive or credential-seeking, but it presents fixed demo finance signals as technical analysis more broadly than the artifacts support.

Review this as a demo-only finance skill. It should not be used for trading or investment analysis unless the publisher replaces the fixed demo values with real validated input data and makes the demo warning visible in every output mode.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The script advertises technical-indicator calculation but actually returns hardcoded demo values based on a fixed price rather than computing from market data. In a finance-related skill, this can mislead users into treating fabricated outputs as real analysis, causing incorrect trading or decision-making even though there is no direct code-execution risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.