Back to skill

Security audit

Alphagbm Hedge Advisor

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent options-hedging advisor, but it can produce concrete trade-like recommendations without enough user caution or consent controls.

Review before installing if you do not want an agent to give concrete options hedge ideas from broad investing prompts. Treat its outputs as educational research only, verify pricing independently, and do not use it as personalized financial advice or trade execution guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger set includes broad phrases such as 'downside protection', 'portfolio hedge', and 'insurance for position', which can activate the skill during generic investing conversations rather than clear user intent to invoke an options-hedging advisor. Because this skill returns concrete hedge trades with live pricing, accidental invocation can steer users toward specific financial actions without sufficiently explicit consent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill delivers ready-to-trade options hedge recommendations with resolved strikes, premiums, and scenario labels, but it does not warn users that outputs are informational only and not personalized financial advice or execution instructions. In a financial context, this omission is dangerous because users may over-trust the recommendation as suitable for their actual risk tolerance, tax situation, liquidity, or suitability constraints.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.