Back to skill

Security audit

A Stock Trading Assistant

Security checks across malware telemetry and agentic risk

Overview

This is a coherent A-share stock assistant that fetches public market data and gives trading-style analysis, with a privacy caution around saved price alerts.

Install only if you are comfortable with the assistant contacting public Chinese finance data providers and with any price alerts you set being saved locally in a watchlist file. Treat its trading suggestions as informational, not personalized financial advice, and delete saved alert data when you no longer need it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger text is broad enough to activate on many ordinary finance or investment discussions, increasing the chance the skill is invoked outside its intended scope. In a trading context, unintended activation can cause the agent to fetch external market data, provide regulated financial guidance, or steer conversations into personalized trading advice when the user did not explicitly request this skill.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the agent to persist user alert settings to a markdown file without explicit notice, consent, retention limits, or access controls. Even if the data seems low sensitivity, stored watchlists and price alerts can reveal investment interests or positions, creating privacy and compliance risk if retained or exposed unexpectedly.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.