Back to skill

Security audit

Alphagbm Fear Score

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed market-analysis skill, but users should treat its options-trading signals as informational rather than advice.

Install only if you want ticker-based options sentiment and timing analysis. Treat the output as a heuristic research signal, not personalized financial advice, and independently verify risk before using it for options trades.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list contains broad phrases such as 'is it fear time', 'when to sell put', and 'oversold reading' that can match ordinary investing conversation and cause the skill to activate outside a clearly scoped request. In a financial skill, unintended invocation can lead to unsolicited trading-oriented guidance, increasing the chance users receive strategy signals they did not explicitly ask for.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly markets a Bull Put Spread entry signal and cites backtested performance without presenting any warning that the output is informational, probabilistic, and not personalized financial advice. In this context, users may over-trust the signal as an actionable recommendation, which can directly influence options trades and lead to financial harm.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.