sector-rotation

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Chinese sector-rotation analysis skill with no code execution, account access, trading authority, or persistence.

Install only if you want Chinese-language sector-rotation heuristics to shape relevant market-analysis conversations. It does not trade or access accounts, but you should verify any investment conclusions with current market data and your own risk limits.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation phrases are broad, generic market-discussion terms such as '板块轮动' and '资金切换', which can cause the skill to trigger in ordinary financial conversations where the user did not intend to invoke a specialized strategy workflow. This creates routing ambiguity and increases the chance of unsolicited or overconfident investment-style guidance being injected into unrelated contexts.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The skill metadata and description are Chinese-only and do not indicate whether the skill supports other user languages or how language selection is handled. In practice this can lead to user confusion, misinterpretation of financial guidance, or incorrect activation behavior when the surrounding conversation is in another language.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal