Back to skill

Security audit

虾皮市场宽度热力图

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused market heatmap analysis guide that uses DaxiAPI data and shows no hidden, destructive, or unrelated behavior.

Install only if you intend to use DaxiAPI for A-share sector heatmap analysis. Use a trusted `daxiapi` CLI, provide only a DaxiAPI token, avoid entering real tokens directly in command history when possible, and treat generated market reports as reference material rather than guaranteed investment advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation instructs users to pass a secret token directly on the command line, which can expose the credential through shell history, terminal logging, screenshots, or process inspection on some systems. Even though this is only documentation, it normalizes an unsafe secret-handling pattern that can lead to credential leakage and unauthorized API access.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.