Back to skill

Security audit

a-share-daily-report-publish

Security checks across malware telemetry and agentic risk

Overview

This skill coherently generates an A-share market recap HTML report, but users should treat its trading strategy sections as informational rather than professional investment advice.

Install only if you want an automated A-share recap generator that queries market-data integrations and writes a local HTML report. Use explicit prompts to avoid accidental runs, verify generated market data independently, and do not rely on the strategy, position-size, or stop-loss language as personalized or professional investment advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
This template does not merely present market data; it embeds explicit trading instructions such as '重点接力', '分歧低吸', '坚决规避', position sizing, stop-loss rules, and next-day action plans. In an agent skill, that changes the behavior from neutral reporting to actionable financial advice, which can cause user harm, compliance issues, and unsafe over-trust in autogenerated recommendations—especially because the report is framed as authoritative and data-driven.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Several trigger phrases such as '市场复盘' and '大盘复盘' are broad enough to match ordinary market commentary rather than an intentional request to run this skill. That can cause accidental activation of a workflow that performs extensive data collection, file generation, and script execution, which increases operational and privacy risk even if the skill's business purpose is legitimate.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.