Back to skill

Security audit

MoltStreet Alerts

Security checks across malware telemetry and agentic risk

Overview

This skill fetches public MoltStreet ETF signal summaries and does not request credentials, persistence, or trading-account control.

Install only if you are comfortable with your agent contacting moltstreet.com for AI-generated ETF signal summaries. Verify important market information independently and do not trade solely from these alerts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation guidance includes generic phrases like "what's worth watching," "alerts," "top picks," and "best opportunities," which are broad enough to match ordinary financial conversation rather than a narrowly scoped skill invocation. The file does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The presentation section prescribes fixed English response text such as "Today's Strongest Signals" and "No high-conviction signals today" with no indication that the agent should adapt to the user's language or locale. This can violate language/locale policy when interacting with users who did not opt into English-only responses.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.