Back to skill

Security audit

trading-plan-generator

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed trading-plan helper that uses a Finskills API key for market data and does not show hidden execution, persistence, or destructive behavior.

Install only if you are comfortable using Finskills as a third-party market-data provider. Use a dedicated API key, avoid sharing unnecessary portfolio details, and independently verify any generated trade plan before acting on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation rules are broad enough to trigger on ordinary finance questions such as general risk/reward or sizing discussions, which can cause the skill to activate outside the user's clear intent. In context, that is risky because the skill then steers the conversation toward live-data trading-plan generation and collection of portfolio/risk details, increasing the chance of over-collection and inappropriate high-risk financial guidance.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to collect account size and maximum risk tolerance, which are sensitive financial details, without an explicit privacy notice, minimization guidance, or justification boundaries. In this context, the data is directly tied to individualized trading advice, so unclear handling of that information can expose users to unnecessary privacy risk and make the interaction more sensitive from a compliance and trust perspective.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.