Finnhub Skill
Security checks across malware telemetry and agentic risk
Overview
This skill appears to be a straightforward Finnhub stock-quote helper that uses a user-provided API key and does not show evidence of hidden or unrelated behavior.
Before installing, confirm you are comfortable giving the runtime access to your Finnhub API key via environment variable. Use a limited API key if possible, avoid pasting the key into prompts or logs, and expect the skill to contact Finnhub to retrieve market data.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
