Back to skill

Security audit

Position Deviation Analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow ETF deviation calculator that uses public market-data APIs and does not show hidden access, persistence, credential use, or destructive behavior.

Before installing, treat this as an informational market-data calculator, not a financial adviser. It may contact Eastmoney with selected ETF ticker codes and may log your OpenClaw user ID plus requested tickers in the runtime logs; avoid relying on it for buy, sell, or position-sizing decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger text is broad enough to activate on general investment questions such as 持仓分析 or 加减仓建议, even though the skill is only intended for a narrow moving-average deviation calculation. In an agentic environment, overbroad routing can cause the model to invoke this skill for unsuitable requests and return misleading finance-related guidance under the appearance of quantitative authority.

Vague Triggers

Low
Confidence
74% confidence
Finding
The example '生成今日投资分析报告' is ambiguous and may prompt invocation for a broad investment-analysis workflow beyond the skill’s actual documented capability. This can lead to user overreliance on output that appears comprehensive, increasing the chance of mis-scoped financial recommendations or hallucinated analysis.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.