Futu Flash

Security checks across malware telemetry and agentic risk

Overview

This skill fetches and formats public Futu flash-news updates from a disclosed Futu endpoint, with no evidence of private data access, persistence, or account-changing behavior.

Install this if you are comfortable with your agent contacting news.futunn.com to retrieve public flash-news data. Be aware the helper script depends on Python requests and may need its shebang adjusted for your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The description includes broad invocation scenarios such as finding the latest N flash items, refreshing, and scrolling updates, which could match common user requests and cause the skill to trigger unexpectedly. Over-broad triggering can redirect ordinary conversations into unsolicited network access and external-content retrieval, increasing the chance of privacy, safety, or UX issues if activated without clear user intent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal