Back to skill

Security audit

Security Options Strategy

Security checks across malware telemetry and agentic risk

Overview

This is a single-file options-analysis skill with broad finance triggers but no hidden execution, credential use, data access, or trading authority.

Install only if you want an options-analysis helper. Verify any time-sensitive regulatory or market claims against official sources, narrow trigger phrases if possible, and do not rely on the skill as licensed financial advice, suitability review, broker pricing, or risk control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list is broad enough to activate on routine finance discussions such as general options pricing, Greeks, or volatility questions, even when the user did not intend to invoke this specific skill. In a finance context, unintended activation can cause the agent to inject domain-specific strategy guidance or assumptions into unrelated conversations, increasing the chance of misleading outputs or inappropriate reliance on this skill.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Several Chinese triggers are especially generic, including terms like '期权开户', '期权权限', or broad market vocabulary that may appear in many benign conversations about brokerage access, education, or regulation. Because the skill provides trading-oriented analysis, accidental activation in these contexts could steer users toward strategy content they did not request, which is more sensitive in a financial decision-making domain.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.