国际实时金价 - 即刻数据

Security checks across malware telemetry and agentic risk

Overview

The skill's code, instructions, and required environment variables match its stated purpose (querying gold prices from jikeapi.cn); there is no evidence of hidden endpoints, excessive permissions, or unrelated behavior.

This skill appears coherent and limited to querying jikeapi.cn for gold prices. Before installing: 1) Only provide an AppKey you expect to be sent to jikeapi.cn — the key is transmitted as a query parameter to the API. 2) Be aware the script will search for the key in environment variables or a .env file next to the script; avoid placing unrelated sensitive secrets in that same directory. 3) The script honors JIKE_API_BASE_URL if set — if you or another component set that env var to an untrusted host, the AppKey could be sent elsewhere, so verify the env in your runtime. 4) Confirm you trust the jikeapi.cn service and its privacy/usage terms before supplying credentials.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal