Dataify Google Finance

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate Dataify Google Finance helper, but it sends finance queries and a Dataify API token to Dataify after user confirmation.

Install only if you intend to use Dataify for Google Finance lookups. Prefer setting DATAIFY_API_TOKEN in the environment instead of pasting tokens into chat or passing them with --token, review the preview table before confirming, and avoid sending private portfolio details or unrelated financial questions unless you want them sent to Dataify.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is broad enough to activate on generic financial-data requests, not just explicit requests to use Google Finance. This can cause the agent to route unrelated finance tasks into this skill, leading to unintended external API use, unnecessary token prompts, and possible disclosure of user queries to a third-party service without clear user intent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to send an Authorization header to a third-party API while hiding that header from the pre-call confirmation table. This reduces transparency around credential transmission and can prevent the user from noticing that a secret is being sent off-platform, increasing the risk of unintended token disclosure to an external service.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal