Market Briefing

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed market-news briefing skill that searches public sources, keeps a small deduplication log, and can send configured Feishu updates.

Install this only if you want recurring market briefings sent through Feishu. Before enabling a cron schedule, verify the chat target, adjust the default topics/language if needed, and avoid putting account tokens, personal holdings, or other sensitive financial details in shared workspace config or memory files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation criteria are overly broad and can trigger on generic market- or geopolitics-related terms, causing the skill to run in situations the user did not explicitly request. Because the skill performs external searches and pushes Feishu messages on activation, accidental invocation can lead to unwanted data retrieval, noisy outbound messaging, and behavior outside user intent.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The skill is hardwired for Chinese-language, China/HK market topics, and specific political/geopolitical keywords without requiring user opt-in. This can override user expectations, produce irrelevant or politically sensitive content, and in combination with the delivery step may send unsolicited localized briefings to Feishu targets.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal