Back to skill

Security audit

Chanlun Analysis Pro

Security checks across malware telemetry and agentic risk

Overview

This is a clearly scoped Chanlun stock-analysis skill, but users should treat its trading signals as educational research rather than financial advice.

Install only if you want Chanlun-style technical-analysis help for research. Do not treat generated buy/sell points, price zones, stop-losses, or position sizes as personalized investment advice; verify market data independently and consider licensed financial advice before trading.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The README explicitly markets buy/sell point generation, trading analysis, and quantitative identification for stocks and indices, but it does not include a clear disclaimer that outputs are educational or informational only and not financial advice. In a trading context, users may reasonably rely on the skill's recommendations for real financial decisions, increasing the risk of harmful or unsuitable actions based on potentially inaccurate AI-generated analysis.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
The README is bilingual, but the actual scope, examples, terminology, and market focus are heavily centered on Chinese A-share use without clearly stating supported locales, data assumptions, or language expectations. This can mislead non-Chinese-speaking or non-A-share users into using the skill outside its intended context, causing misunderstanding of outputs, incorrect market assumptions, or misuse of analysis templates.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The trigger list includes broad phrases like stock market analysis, quantitative trading, and Python Chanlun without meaningful scoping, which can cause the skill to activate in contexts far beyond the author's intended use. Over-broad invocation increases the chance of the agent offering unrequested financial guidance or being selected over safer, more specialized skills in ambiguous prompts.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill gives concrete trading recommendations, price zones, stop-losses, and tactical suggestions without an explicit user-facing risk warning or suitability disclaimer. In a financial-advice context, this is dangerous because users may treat speculative pattern-based outputs as actionable advice, leading to monetary loss and potential compliance or trust issues.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document gives highly actionable trading guidance, including entry points, stop-loss rules, position sizing, and execution checklists, but does not present a prominent financial-risk disclaimer or warning that losses can occur and that the material is educational rather than personalized advice. In a skill context, this increases the chance that users treat the content as prescriptive investment advice and suffer financial harm from following it uncritically.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.