Back to skill

Security audit

Quant AI Chart Analysis

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: it sends chart screenshots to Quant AI for educational chart analysis, with no evidence of hidden execution, persistence, trading, or account access.

Before using this skill, confirm you are comfortable sending the screenshot to Quant AI. Redact account names, balances, order IDs, watermarks, or proprietary trading information, and treat the output as educational rather than financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to upload a user-provided chart screenshot to a third-party website, but it does not disclose that user data will leave the system or warn about privacy and confidentiality implications. Even if chart screenshots seem low risk, they may contain account names, positions, timestamps, watermarks, or proprietary trading information that could be exposed to an external service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.