Back to skill

Security audit

Alphagbm Options Strategy

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent options-strategy helper that discloses its AlphaGBM API use and does not include code, persistence, or hidden local access.

Before installing, understand that using real-data mode may send ticker symbols, market views, risk preferences, and strategy parameters to AlphaGBM under your API key. Avoid entering account credentials, portfolio holdings, or private financial details unless you trust that provider, and treat generated options strategies as research rather than trading instructions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
95% confidence
Finding
The skill sends user-provided trading inputs to an external API service but does not clearly warn users that their ticker selections, market views, and related trade-planning data may be transmitted off-platform. While this is not direct code execution or credential theft, it creates a privacy and transparency issue because users may unknowingly disclose potentially sensitive financial intent or strategy information to a third party.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.