a-stock-ai-research

Security checks across malware telemetry and agentic risk

Overview

This is a simple prompt-only A-share research helper; its triggers are broad, but it does not install code, access accounts, or handle credentials.

Installers should treat this as a research-assistance prompt, not financial advice. Because the activation examples are broad, use it when you explicitly want A-share investment analysis, and verify summaries, forecasts, and any investment decisions against authoritative market sources.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are generic, conversational requests like asking to analyze a report, announcement, or stock, which are likely to overlap with ordinary user prompts outside the intended A-share research workflow. This can cause accidental invocation, routing user data into the skill unexpectedly, and producing investment-oriented outputs when the user did not explicitly opt into this skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal