Back to skill

Security audit

HyperGrok Desk Monitoring

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only trading-desk monitoring guide that clearly limits watches to fetching, logging, and alerting rather than trading.

Install this only if you want agents to help monitor a trading desk or account. Watches may read sensitive account and market data and write local logs or briefs, so confirm any routine schedule, alert destination, and data source before enabling it.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill description includes broad activation phrases such as 'briefings', 'alerts', 'watch X', and 'scheduled checks', which can cause the skill to trigger on a wide range of user requests. In an automation-oriented trading context, overbroad invocation increases the chance the skill is selected unexpectedly and may start monitoring workflows or produce market/account outputs when the user intended something narrower.

Static analysis

No suspicious patterns detected.