Security audit
Infoway Financial API — Real-Time Quotes, Klines & Analysis
Security checks across malware telemetry and agentic risk
Overview
This appears to be a disclosed Infoway financial market-data MCP server that uses an API key to fetch quotes and fundamentals, with no evidence of hidden or destructive behavior.
Install only if you are comfortable giving this MCP server an Infoway API key and allowing it to contact Infoway for financial market data. For tighter supply-chain control, install it in a virtual environment and review the PyPI package and infoway-sdk dependency before use.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
