Back to skill

Security audit

Alphagbm Marks Cycle

Security checks across malware telemetry and agentic risk

Overview

The skill is simple and non-executable, but it gives broad, direct trading posture recommendations without clear risk framing or explicit user control.

Review before installing if you do not want a skill that may answer broad market questions with action-oriented trading posture. Treat its output as a rough market sentiment indicator, not personalized financial advice, and independently verify data, suitability, and risk before acting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad natural-language investment questions that can match ordinary user intent beyond a narrowly scoped skill invocation. This raises the risk of unintended activation and unsolicited financial guidance, especially because the skill returns posture recommendations like offense versus defense that can influence decisions without the user explicitly choosing this tool.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill provides direct investment-action prescriptions such as 'Buy aggressively,' 'sell vol,' 'don't add,' and 'buy protection' without any informational-only disclaimer or warning about financial risk. In context, this is more dangerous because the skill is explicitly designed as a one-call market posture signal, making it easy for users to treat output as actionable advice rather than a rough sentiment indicator.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.