Back to skill

Security audit

Alphagbm Macro View

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent, but it can use an external API to retrieve portfolio-linked financial analysis under broad triggers.

Install only if you are comfortable giving this skill an AlphaGBM API key and allowing it to retrieve analysis tied to your holdings or profiles. Use clear, explicit requests, and avoid letting it run on vague macro or yield mentions unless that is intended.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes very broad terms such as "宏观", "macro", "yield", and symbols like "VIX" that can appear in many benign conversations, which can cause unintended invocation of the skill. Because the skill accesses portfolio-linked macro analysis from an external service, accidental activation can expose user financial context or produce actions the user did not clearly request.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill states that impact analysis is linked to the user's actual holdings, but it does not clearly warn the user that holdings-linked data will be processed by an external API. This creates a privacy and consent risk because sensitive financial portfolio context may be transmitted or inferred without an explicit user-facing disclosure.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.