Back to skill

Security audit

InvestToday Finance Data

Security checks across malware telemetry and agentic risk

Overview

This finance-data skill is mostly aligned with its purpose, but setup promotes an under-explained background updater that can change the CLI and installed skills, and some finance reference examples are unreliable.

Review before installing. Use this as a data-retrieval and research aid, not as investment advice or an automated trading tool. Avoid the auto-update init path unless you intentionally want a background scheduled task that can update the CLI and installed skills; prefer disabling auto-update and verify all financial outputs against primary sources, especially where the docs contain mismatched examples.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The output example for the 基金申购赎回状态 endpoint includes fields and a remark that appear unrelated to fund subscription/redemption status, such as a business-system style object name and a product-release note. This indicates documentation/data contamination or schema mix-up, which can mislead downstream agents into treating unrelated text as trusted financial data and may cause incorrect decisions, prompt injection propagation, or accidental disclosure of internal business context.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The `backgroundDesc` example contains bank-client business, revenue, VIP status, credit history, and loan details that are unrelated to a fund manager information API. This indicates likely cross-domain data contamination or unsafe reuse of real/sensitive sample text, which can expose private financial information and mislead downstream users about the API's actual data contract.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The output field examples for a fund fee API are contaminated with unrelated electricity pricing and power-capacity descriptions, which indicates documentation/data integrity failure. This can mislead downstream agents or users into mis-parsing fields, generating incorrect financial analysis, or trusting structurally invalid examples when building automations against the skill.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The '货币市场质押式回购指标' section describes a money-market repo interface, but its narrative explanation was copied from the government bond yield API. This documentation mismatch can cause an agent or downstream developer to call the tool with the wrong expectations, misinterpret returned fields, and produce incorrect macro/interest-rate analysis in a finance context.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation for the litigation/arbitration endpoint contains output examples that clearly do not match the stated purpose, mixing legal-case fields with unrelated business, logistics, and project-status content. This can mislead an agent into misclassifying data, producing incorrect legal or financial risk analysis, and propagating false conclusions in downstream investment workflows.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The example output for a bank stock includes a drug-regulatory approval statement, which is clearly inconsistent with the financial-analysis context. This kind of schema/example corruption can mislead downstream agents or users into treating irrelevant or fabricated data as valid investment evidence, reducing trust and potentially distorting financial reasoning.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
Several example fields in the main-business endpoint contain content unrelated to a bank stock, including chip R&D, Apple channels, and raw-material capacity. In an agent setting, such mismatched examples can poison prompts, mappings, or evaluation logic, causing the model to infer false business attributes and generate materially misleading investment analysis.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The sample output exposes detailed customer and lending information in a field documented for fund manager background information, which is a strong sign of unintended disclosure of unrelated personal and financial business data. In a finance-data skill, such leakage is especially dangerous because consumers may treat documentation examples as representative, reuse them in tests, logs, or prompts, and propagate sensitive information further.

Missing User Warnings

Low
Confidence
95% confidence
Finding
The documentation explicitly states the endpoint is suitable for stock analysis and investment decision-making, but it provides no caution that the data is informational only and not personalized financial advice. In a finance-focused skill, this can encourage overreliance on scoring outputs for trading or investment decisions, increasing regulatory, compliance, and user-harm risk.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The endpoint is explicitly framed as supporting investment risk assessment and decision support, but the documentation does not prominently warn that outputs are informational only and should not be treated as personalized financial advice. In a financial skill, this increases the chance that users or downstream agents over-rely on generated analysis for real investment decisions, especially when paired with authoritative-looking structured data.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The document exposes explicit trading-signal content such as buy/sell dates, prices, stop-loss, take-profit, position sizing, win rates, and returns, but does not include a clear warning that the outputs are informational only and not financial advice. In an agent skill, this increases the chance that downstream systems or users treat the signal as actionable investment guidance, creating compliance, misuse, and user-harm risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.