Sentiment Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware-like, but it claims to analyze real stock sentiment while returning random mock results that could mislead users.

Review before installing or relying on this skill. Treat its output as demo/mock data, not an investment or operational signal, unless the author clearly implements real data collection and sentiment analysis and labels any synthetic output explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The module claims to perform real stock comment scraping and NLP-based sentiment analysis, but the implementation generates random values instead. In a financial-analysis context, this is dangerous because downstream users or agents may rely on fabricated outputs as if they were evidence-based signals, leading to misleading decisions and loss of trust.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal