Back to skill

Security audit

Alphagbm Theme Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AlphaGBM integration for organizing investment themes, with no hidden code or local persistence found.

Install this if you are comfortable letting an agent use your AlphaGBM API key to read and manage your saved investment themes, tickers, and news keywords. Confirm create, update, and delete requests before allowing them, especially because deleting a theme is described as a hard delete.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger guidance includes very generic terms such as "主题", "theme", "basket", "篮子", and "板块", which can cause the skill to activate for broad, ambiguous finance conversations not specifically asking for theme-research actions. In this skill, unintended invocation could expose portfolio/theme data or cause accidental create/update/delete operations if the agent routes user intent incorrectly.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.