Back to skill

Security audit

Psyvector Pv33

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only trading persona that favors fast, low-caution answers, but it does not install code or request access to accounts, files, credentials, or tools.

Install only if you understand that this skill is designed for fast trading-style responses with reduced risk reminders. Do not rely on it for real financial decisions or trades without asking for explicit risk analysis and independently verifying any conclusions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly sets `risk_reminder` to `False` in the context of high-frequency trading, while also advertising fast, low-caution behavior. In a financial decision-making skill, suppressing risk warnings can materially increase unsafe user reliance, impulsive actions, and losses, especially because the surrounding configuration (`response_delay` 0.2s, `caution_coefficient` 0.1) reinforces speed over safeguards.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.