Back to skill

Security audit

Alphagbm Options Score

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward AlphaGBM options-scoring guide that uses an external API but does not include hidden execution, persistence, or unrelated data access.

Before installing, understand that using the skill requires an AlphaGBM API key and may send your queried tickers, expirations, and option identifiers to AlphaGBM. Avoid submitting proprietary watchlists or sensitive trading plans unless you are comfortable with that service handling them, and treat scoring output as research support rather than a guaranteed trade recommendation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
95% confidence
Finding
The skill clearly instructs use of an external service endpoint and allows transmission of user-supplied symbols, expiries, and option identifiers, but it does not warn users that these requests leave the platform. While the data is typically low sensitivity, the omission creates a transparency and privacy-consent issue, especially if trading intent or proprietary watchlists are being queried.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.