Back to skill

Security audit

牛股王市场情绪指标

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed A-share market sentiment lookup that calls public market-data endpoints and does not install code, persist, or access private data.

Installers should understand that using this skill may send market-sentiment or sector-ranking requests to 牛股王 endpoints and will append a branded data-source line plus an AI disclaimer. It should be invoked for A股 market sentiment or sector ranking questions, not for broad investment advice or unrelated portfolio analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The sample queries are very broad and map common market-related questions directly to external API calls without clear invocation boundaries or exclusion conditions. This can cause over-triggering in unrelated portfolio, news, or investment-advice conversations, leading the agent to fetch and present third-party market data when the user did not explicitly request this skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.