Back to skill

Security audit

Alphagbm Vol Surface

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed AlphaGBM options-volatility analysis helper with no hidden code, persistence, or destructive behavior.

Before installing, users should understand that ticker requests and the configured AlphaGBM API key may be used with AlphaGBM's external service, and financial outputs should be independently verified before trading decisions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.