Back to skill

Security audit

A股分时量能分析

Security checks across malware telemetry and agentic risk

Overview

The skill coherently provides A-share market analysis and local portfolio tracking, with no evidence of credential use, exfiltration, or hidden execution.

Install only if you are comfortable storing your portfolio details locally and sending queried stock codes to Sina Finance for market data. Review add, update, and remove commands before running them because they change the saved local portfolio file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly documents add, update, and remove portfolio commands that write to a persistent local file under the user's home directory, but it does not warn that these operations modify local state. In an agent setting, a user may believe they are only performing analysis while the skill silently changes or deletes portfolio data, creating integrity and privacy risks through unintended state changes.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal