Back to skill

Security audit

Alphagbm Watchlist

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward watchlist helper, with expected account watchlist changes that users should treat as persistent actions.

Before installing, understand that commands like adding, watching, or removing symbols may change your saved watchlist. Use explicit wording for write actions and review bulk changes before allowing the agent to call POST or DELETE watchlist endpoints.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
94% confidence
Finding
The skill explicitly supports state-changing watchlist operations through add/remove commands and corresponding POST/DELETE endpoints, but it does not warn users that these actions may persistently modify account data. This can lead to unintended account changes if the agent executes an ambiguous or mis-triggered request, especially because natural-language triggers like 'watch NVDA TSLA META' may be interpreted as a write action rather than a read-only query.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.