Back to skill

Security audit

Stock Evaluator

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only stock research skill with no hidden code or trading-account access, but users should treat its outputs as research because it gives trading-style recommendations and has some data-quality risks.

Install only if you want an agent to perform detailed stock research and produce explicit trading-style recommendations. Verify every cited metric, news item, insider-trading value, and currency conversion independently, watch for unreplaced dashboard placeholders, and do not treat the output as personalized professional financial advice or the sole basis for a trade.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The guide imposes strict verified-source requirements for core financial metrics, but leaves TOP NEWS and sentiment inputs unspecified even though they materially influence the dashboard and recommendation context. That gap can allow unverified or manipulated headlines/sentiment to be presented alongside trusted metrics, creating a misleading veneer of rigor and potentially biasing investment decisions.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill declares a strict zero-fabrication policy, but the embedded required dashboard template contains concrete placeholder prices, dates, ratios, news, and chart data while also instructing the model not to leave placeholders. This creates an instruction conflict that can cause the agent to emit fabricated financial analysis if real data is unavailable, undermining data integrity and potentially producing misleading investment recommendations.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill explicitly says missing insider data must be displayed as N/A and that zero must never be substituted for unavailable data, yet the template initializes insider buys and sells to 0. This can silently convert unknown regulatory trading data into a false factual claim, skewing sentiment and governance assessment in an investment recommendation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The workflow instructs the agent to produce explicit BUY/HOLD/SELL recommendations, entry and exit prices, stop losses, and position sizing, but the file contains no corresponding user-facing warning that this is general financial analysis rather than personalized investment advice. In context, this is more dangerous because the skill is specifically designed to influence investment decisions, so users may reasonably rely on it and incur financial losses if the advice is unsuitable for their circumstances.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
Forcing Euro as the default currency without user opt-in can misrepresent prices, valuation thresholds, and position-sizing outputs when the underlying security or user context is denominated in another currency. In an investment skill, this context increases the danger because users may act on incorrect currency assumptions and make materially wrong trading decisions.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The implementation instructions mandate Euro formatting for all outputs with no locale or source-currency choice, which can systematically distort financial interpretation across global equities. Because the skill produces explicit entry, stop-loss, and valuation numbers, this creates a real risk of user harm through unit confusion rather than being a harmless formatting preference.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.