Back to skill

Security audit

Alphagbm Stock Analysis

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent stock-analysis integration, but it gives buy/sell-style investment recommendations without clear financial-risk guardrails and may trigger on broad investing questions.

Review this carefully before installing. It may answer ordinary stock questions with third-party buy/sell-style recommendations, and it sends ticker requests with your AlphaGBM API key to the configured AlphaGBM service. Treat outputs as research signals only, verify market data independently, and do not rely on the skill for personalized investment, tax, or legal advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are very broad and overlap with ordinary investing questions like 'should I buy TSLA' or 'what do you think about NVDA', which increases the chance this skill is invoked when the user did not explicitly ask for this specific tool or framework. In an agent ecosystem, overbroad invocation can route users into a third-party financial analysis workflow unexpectedly, creating reliability, consent, and policy risks around financial advice.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill is designed to return actionable buy/sell-style outputs, composite scores, and recommendations, but it does not include a clear disclaimer that the output is informational, may be inaccurate, and is not personalized investment advice. That is dangerous because users may over-rely on the model's recommendation for regulated or high-stakes financial decisions without understanding its limits or the need to consider jurisdiction, suitability, and risk tolerance.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.