Back to skill

Security audit

Quant Research Platform

Security checks for vulnerabilities and agentic risk

Overview

This is a local quantitative research helper with normal data-science dependencies and no evidence of hidden access, persistence, exfiltration, or destructive behavior.

Install the dependencies in a virtual environment and pin versions for serious use. Treat the project as research/demo code, validate any trading logic before relying on it, and only use market or alternative data sources when you have the proper license, consent, and compliance basis.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly promotes alternative data sources such as satellite imagery, web traffic, and supply-chain data, which can involve third-party collection, transmission, licensing, and potentially sensitive or regulated information. Presenting these capabilities without any privacy, consent, jurisdiction, or third-party access warning can lead users to ingest or transmit data in ways that violate policy, contracts, or compliance requirements.

Static analysis

No suspicious patterns detected.