Back to skill

Security audit

Trump Tback

Security checks across malware telemetry and agentic risk

Overview

This skill is a local Trump-post sentiment and market-momentum analyzer, with no evidence of hidden data access, persistence, trading, purchasing, or destructive behavior.

Install only if you want a research-style sentiment analyzer for Trump-related posts. Treat its market warnings as non-investment analysis, confirm before using broad triggers like Iran or market sentiment, and review future versions carefully if they add live social-media fetching, credentials, trading, or purchase capabilities.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes generic political and market terms such as '伊朗', '贸易战', '市场情绪', and 'Trump mood', which can cause the skill to activate in conversations that merely mention these topics rather than explicitly requesting this tool. That increases the chance of unintended invocation, context hijacking, or routing users into a specialized analysis flow they did not ask for.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal