Back to skill

Security audit

Stock Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed CellCog financial-analysis integration, with a privacy caveat around the personal financial examples it encourages users to provide.

Before using this skill, treat prompts as data sent to CellCog and avoid sharing account numbers, SSNs, tax IDs, brokerage credentials, or unnecessary personally identifying details. Use aggregated or redacted financial figures when possible, and verify any investment or tax recommendations with an appropriate professional.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly invites users to submit highly sensitive personal financial, portfolio, income, debt, and tax information, but provides no privacy notice, minimization guidance, or warning about how that data may be transmitted to or processed by a third-party service. In this context, users may overshare regulated or high-risk financial data under the assumption that it is safe, creating avoidable confidentiality and compliance exposure if the data is retained, logged, or mishandled.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.