Back to skill

Security audit

Alphagbm Investment Thesis

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly coherent for tracking investment theses, but it can modify and hard-delete financial research records with broad activation wording and no documented deletion safeguard.

Review this skill before installing if you use AlphaGBM for real portfolio research. It needs an API key and can create, update, and delete persistent thesis records. Use it only for clear investment requests, and require explicit confirmation before any delete action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrase "update my thesis" is broad enough to activate on ordinary conversation that is unrelated to investment theses. In an agentic environment, this can cause unintended invocation of the skill and subsequent read/write operations against thesis records, especially because the skill supports modifying existing data via follow-on API calls.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance is ambiguous because it activates on generic terms like "thesis" and broad Chinese keywords without requiring investment context. This increases the chance of accidental routing from unrelated user requests, which is particularly risky because the skill can retrieve and alter financial records tied to positions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes a hard-delete operation for theses without documenting any confirmation, safeguard, or soft-delete alternative. If invoked accidentally or through misrouting, the action can permanently erase investment rationale and trigger history, undermining auditability and potentially causing financial decision errors.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.