Back to skill

Security audit

Einstein Research — Macro Regime Detector

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed market-analysis tool that fetches financial data and writes local reports, with no evidence of hidden access, persistence, or destructive behavior.

Before installing, be comfortable providing an FMP API key and allowing the script to contact Financial Modeling Prep for public market data. Treat the output as informational market analysis, not personalized investment advice, and choose an output directory where generated JSON and Markdown reports are expected.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill declares no required tools or permissions, yet its documented workflow explicitly uses environment variables, network access to an external API, and file writes for report generation. This is dangerous because the platform or user may grant broader capabilities than expected without informed consent, undermining least-privilege controls and making hidden data access or persistence harder to audit.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The stated description frames the skill as analytical market-regime detection, but the documented behavior also includes external API calls, API key consumption, local file generation, and a script-driven orchestration flow. That mismatch is risky because users and reviewers may assess it as a simple analysis skill while overlooking data egress, credential use, and filesystem side effects that require separate trust and permission scrutiny.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The guide includes direct action language such as 'Execute repositioning' and 'Complete repositioning' without any caution that the material is educational or that financial decisions require suitability, risk, and time-horizon assessment. In a skill explicitly designed to detect macro regime shifts and inform long-term market positioning, this can cause users or downstream agents to treat heuristic signals as prescriptive investment advice, increasing the chance of harmful financial decisions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.