Back to skill

Security audit

Outer Ratio Monitor

Security checks across malware telemetry and agentic risk

Overview

This skill is a stock-monitoring helper that fetches public market data and stores local history; its sensitive behaviors are limited and mostly disclosed.

Before installing, understand that this is a financial signal tool, not investment advice, and it records stock watchlist history locally under ~/.openclaw/memory/stocks. Review or edit the watched stocks and thresholds before running it; do not rely on its marketing claims as trading guidance.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises 'zero dependency' market monitoring but exposes capabilities for network access, file writes, and environment use without any declared permissions or clear upfront disclosure. Hidden or undeclared capabilities increase the chance that a user or platform will authorize behavior they did not expect, especially because the skill stores data under the user's home directory and sends alerts externally.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The documented purpose does not fully match the actual behavior: the skill persists historical and snapshot data locally, supports additional CLI modes, and references DingTalk despite emphasizing Feishu. Behavior mismatches are dangerous because they undermine informed consent and can conceal data retention or exfiltration paths that users and reviewers are not expecting.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The script silently persists trading watchlist activity and historical monitoring data under the user's home directory without any runtime notice or consent flow. In this skill context, the data is not highly sensitive by itself, but undisclosed persistence can leak behavioral or financial-interest information to other local processes/users and creates privacy risk on shared systems.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.