Back to skill

Security audit

Alphagbm Iv Rank

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward IV-rank market-data helper with a disclosed AlphaGBM API dependency and no hidden execution, persistence, or account-changing behavior.

Before installing, understand that requested ticker symbols and related query parameters may be sent to AlphaGBM, and keep proprietary watchlists or strategy context out of prompts unless you are comfortable sharing them. Do not rely on the generated buy/sell-premium suggestions as personalized financial advice.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs use of an external API but does not clearly warn users that their ticker queries may be transmitted off-platform. Even though ticker symbols are usually low-sensitivity data, user queries can include proprietary watchlists, trading intent, or strategy context, creating a privacy and data-handling risk if sent to a third party without transparency.

Static analysis

No suspicious patterns detected.