Back to skill

Security audit

Sector Overview

Security checks across malware telemetry and agentic risk

Overview

This is a small sector-analysis skill whose report-writing and optional note creation are disclosed and aligned with its purpose, though users should expect persistent analysis artifacts.

Install if you want automatic sector-analysis reports. Be aware that using it can save markdown reports in the working directory and may create IMA reminder notes for detected market signals; avoid using it for confidential financial queries unless that persistence is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic requests such as '行业分析' and '哪个板块有机会', which can easily overlap with normal conversation and cause unintended skill activation. In an agent setting, overbroad invocation can lead to unexpected tool use, unnecessary downstream data access, or file creation without the user clearly intending to invoke this skill.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README states that the skill writes a Markdown report to disk, but it does not prominently warn users or operators about this side effect. Undisclosed file writes can create privacy, persistence, and workspace integrity risks, especially if reports contain sensitive financial queries or analysis artifacts that users did not expect to be stored.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are overly broad and map to common, ordinary market questions, which can cause the skill to activate when the user did not explicitly request this workflow. Because the skill performs downstream actions such as data collection and report generation, over-triggering can lead to unintended tool use, unnecessary data processing, and unexpected side effects in response to casual prompts.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill specifies writing reports to the working directory and creating IMA notes, but it does not disclose these side effects to the user in a user-facing way or require consent. Hidden persistence and note creation are dangerous because a simple analysis request can silently create artifacts in the workspace or external note systems, violating user expectations and potentially leaking sensitive analytical context into persistent storage.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.