Back to skill

Security audit

Alphagbm Vix Status

Security checks for vulnerabilities and agentic risk

Overview

This is a simple VIX interpretation skill with no code execution, persistence, credential access, or hidden data handling, but users should treat its trading hints as risky informational guidance.

Install only if you want market-volatility summaries with options-trading hints. Treat the strategy text as educational, verify current market data independently, and do not rely on a VIX tier alone for financial decisions.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger list is broad enough to match ordinary market conversation such as general questions about VIX, fear, or whether the market is calm. That can cause the skill to activate outside a clearly intentional finance-advice workflow, increasing the chance that users receive unsolicited or context-poor trading guidance.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill gives direct, actionable trading instructions such as actively opening positions, halving size, buying protection, or buying the dip, but it does not provide any risk warning, suitability caveat, or statement that this is informational rather than personalized financial advice. In a finance context, that makes the content more dangerous because users may over-rely on a single indicator and act on the recommendation without understanding loss potential or limitations.

Static analysis

No suspicious patterns detected.