Back to skill

Security audit

Finance News Aggregator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only news aggregation skill with some labeling drift, but no included executable code, credential handling, persistence, or destructive behavior was found.

Install only if you want a reference skill for AI and finance news aggregation. Treat the market-impact and risk sections as informational, verify sources before acting, and review any separate Python scripts you choose to deploy because those scripts may contact RSS feeds or third-party APIs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill materially expands from AI/technology news aggregation into finance-news aggregation, market-impact commentary, and sentiment/risk workflows that are not disclosed in the manifest. This scope drift can mislead users, policy gates, and reviewers into enabling a skill with more sensitive financial-analysis behavior than advertised, increasing the chance of inappropriate use or bypass of stricter review requirements.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The document claims the skill is only an educational reference and contains no executable code, yet it provides concrete commands and identifies runnable scripts as core functionality. This contradiction can cause reviewers and users to underestimate operational risk, especially network access, third-party data transmission, and local execution of referenced tooling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.