mx-financial-assistant

Security checks across malware telemetry and agentic risk

Overview

The skill is internally consistent: it calls an EastMoney assistant API, only requires a single EM_API_KEY, and the included script and instructions match the described financial-Q&A purpose.

This skill appears to do what it says, but consider the following before installing: (1) The script will send user queries (and any content you provide) to https://ai-saas.eastmoney.com — verify that this endpoint and the API key provider (EastMoney) are acceptable for your data/ privacy needs. (2) EM_API_KEY is the only credential required; treat it as sensitive: use a scoped/limited key if possible and do not reuse privileged credentials. (3) SKILL.md requests installing the Python httpx package — ensure you install packages from trusted registries in a controlled environment. (4) Avoid sending sensitive PII or confidential data to the remote API, since queries and responses traverse an external service. (5) If you need higher assurance, verify the API provider’s documentation/terms and consider running the skill in an isolated environment or reviewing network traffic to confirm behavior.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal