Back to skill

Security audit

Stock Inquiry - 股票查询

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward stock lookup wrapper for JisuAPI, with no hidden persistence, destructive behavior, or unrelated local access found.

Install this only if you trust JisuAPI and are comfortable using a JISU_API_KEY. Stock symbols, list parameters, and your API key will be sent to JisuAPI and may affect your provider quota or billing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation description uses broad phrasing such as '或类似个股行情、股票列表问题时,使用本技能', which can cause the agent to invoke the skill for loosely related finance queries without clear boundaries. Over-broad routing increases unintended third-party data disclosure and makes it harder for users to understand when external services will be contacted.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation describes a third-party JisuAPI integration but does not provide a clear user-facing warning that requested stock codes and related query parameters are transmitted to that external service. This is a privacy and transparency issue because users may assume the assistant answers locally when their financial interests or watchlist queries are actually being shared externally.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.