Alpha Pulse 1.0.0

Security checks across malware telemetry and agentic risk

Overview

This is a mostly straightforward stock-market data scanning skill, but its documentation overstates features that are not implemented.

Install dependencies in a virtual environment, review any optional market-data token before adding it, and treat the trading predictions as unproven because this package only includes a basic scanner rather than the full prediction/reporting/notification system it advertises.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill text indicates it will immediately create `config.yaml` and `lib/scanner.py` and frames this as requiring no user action, but it does not explicitly disclose that this means writing files into the user's workspace. In an agent context, undeclared file creation can bypass user expectations and consent boundaries, increasing the risk of unwanted modifications or persistence.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal