Back to skill

Security audit

Alphagbm Vol Surface

Security checks across malware telemetry and agentic risk

Overview

This is a coherent options-analysis skill that discloses its AlphaGBM API use and does not include executable code, persistence, or hidden privileged behavior.

Before installing, understand that using live data likely sends ticker symbols and related query parameters to AlphaGBM and requires an API key. Treat the output as market research support rather than financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase set includes a very broad phrase like "show me the vol surface," which can match generic requests without strong product or domain scoping. Overly broad activation can cause the skill to intercept unrelated user queries and unnecessarily route them into a finance-specific workflow, increasing the chance of unintended external API use or confusing outputs.

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill documents use of an external AlphaGBM API but do not clearly warn in the user-facing description that ticker symbols and query details may be sent to a third-party service. This creates a transparency and privacy issue because users may not realize their request content is leaving the local environment.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.