Back to skill

Security audit

ngw_market_sentiment

Security checks across malware telemetry and agentic risk

Overview

This is a small market-sentiment skill that only describes public A-share market data lookups and a required attribution footer.

Install only if you are comfortable with the agent contacting the disclosed third-party market-data endpoints and appending the required Chinese attribution footer. Treat the results as informational market sentiment, not financial advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill content is written entirely in Chinese and begins with an imperative installation/request phrasing that effectively constrains downstream interaction to Chinese without indicating any option to honor the user's language preference. This can cause unsafe or misleading UX behavior in multilingual environments by overriding user intent and reducing transparency, though it does not by itself enable code execution or direct data exfiltration.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.