Back to skill

Security audit

Dfw Trading Signals

Security checks across malware telemetry and agentic risk

Overview

The skill does not show malware behavior, but it materially overstates its trading-analysis capabilities and gives actionable financial guidance without adequate risk disclosure.

Review before installing or relying on it for trading. Treat outputs as rough informational signals, not financial advice or validated probabilities. Do not rely on the advertised confidence intervals, backtests, regime detection, or whale-flow analysis unless the implementation is updated and independently verified; use a limited CoinGecko key and be aware that unpinned dependencies will be installed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill provides concrete trading signals, confidence scores, invalidation levels, and position-sizing guidance without a clear warning that outputs are probabilistic and can cause financial loss. In this context, the lack of a prominent non-advisory and risk disclaimer makes the skill more dangerous because users may over-trust apparently quantitative outputs as authoritative investment advice.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.