Gold News Sentiment

Security checks across malware telemetry and agentic risk

Overview

This skill coherently fetches public gold-related news, analyzes sentiment, and stores local cache files without evidence of hidden credential use, destructive behavior, or unrelated data access.

Install only if you are comfortable with a skill that runs bundled Python scripts to query Google/Bing News and write local cache files for faster future sentiment reports. Treat the output as market analysis support, not financial advice, and enable recurring updates only deliberately with a clear schedule.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding
The skill instructs the agent to execute networked scripts and update local files, but the manifest shown does not declare corresponding permissions. That mismatch can undermine permission gating and user/operator expectations, especially for a skill that fetches remote content and writes cached artifacts. In this context the behavior appears functionally intended, but undeclared capabilities increase the chance of silent overreach rather than reflecting a harmless documentation issue.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal