Tushare Pro
Security checks across malware telemetry and agentic risk
Overview
This skill is a straightforward Tushare market-data helper that requires a user-provided API token and does not show hidden or destructive behavior.
Install this only if you intend to use Tushare and are comfortable providing a Tushare API token. Treat the token like a password, consider using a limited or low-risk account if available, and install the Python dependencies in an environment you trust. The signup link includes a registration parameter, so use the main Tushare site directly if you do not want that parameter used.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
66/66 vendors flagged this skill as clean.
