Technical Analysis

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only technical-analysis education skill with financial-risk caveats missing, but no hidden code, data access, persistence, or automatic trading authority.

Install only if you want educational technical-analysis guidance. Do not treat its chart patterns, stop-loss examples, or risk percentages as personalized investment advice, and confirm that the assistant is using this skill intentionally when your question is only loosely related to markets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes very broad terms such as trading, trend, support, resistance, and stock market, which can match many ordinary conversations and cause the skill to activate outside clear user intent. In a financial context, unintended activation is risky because it may inject trading guidance into ambiguous situations and influence decisions without the user explicitly asking for this skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The statement that the skill will appear whenever it 'senses this book could help' creates an ambiguous and effectively open-ended activation condition. This increases the chance of unsolicited financial advice or over-triggering in loosely related conversations, which is especially problematic for a skill that includes tactical trading recommendations.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill gives concrete trading tactics such as when to sell, where to place stops, and how much to risk, but does not pair those instructions with a clear financial-risk disclaimer or statement that the content is educational and not personalized investment advice. In this context, users may over-rely on the guidance as actionable advice, increasing the chance of financial harm.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal