Back to skill

Security audit

Trading Journal

Security checks across malware telemetry and agentic risk

Overview

This is a simple trading journal skill whose local file storage is disclosed and fits its purpose, though users should remember the saved notes may contain sensitive financial information.

Before installing, understand that entries may include positions, strategy, emotions, lessons, and performance data saved locally under the listed trading workspace paths. Use it on a device/account where local files are appropriately protected, and manually remove or redact sensitive records if needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill explicitly documents persistent storage paths for trading journals, shadow portfolios, and reports, but does not warn users that potentially sensitive financial notes and performance data will be written to local files. This creates a privacy and data-handling transparency issue: users may disclose strategy, positions, or emotional notes without realizing the data persists on disk and could be accessed by other local processes or users.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.