prana-astock-financial-analysis

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed remote Prana financial-analysis client that sends the user's prompt and API key to declared Prana endpoints, with no evidence of hidden execution or unrelated data access.

Install only if you trust Prana and claw-uat.ebonex.io with your financial-analysis prompts. Prefer a temporary environment variable for one-off use, use global key storage only on a trusted machine, and avoid sending confidential company, customer, account, or trading information in the prompt.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The script sends the user-provided question to a remote Prana service over the network, but there is no explicit user-facing disclosure at execution time that potentially sensitive financial-analysis prompts will leave the local environment. In a skill context that mandates remote agent invocation, this behavior is expected, but it still creates a real privacy and data-handling risk if users include confidential company, customer, or internal research data without informed consent.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal