Back to skill

Security audit

Fubon Cli

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Fubon trading helper, but it gives an agent live brokerage order authority without strong confirmation and secret-handling controls.

Install only if you intentionally want an agent to help operate Fubon brokerage workflows. Start with read-only quotes and account queries, verify package sources, keep credentials and certificates out of chat and logs, and require explicit confirmation for every order, cancellation, modification, conditional order, or retry.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger description is broad enough to activate this skill for generic trading or command-line automation requests, which can route users into a real-money brokerage workflow without a sufficiently explicit opt-in. In the context of a trading skill that supports login and order placement, overbroad activation increases the chance of unintended execution paths and unsafe assistance around financial transactions.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill describes end-to-end order workflows and provides concrete buy/sell commands, but it does not prominently warn that these commands may place live trades affecting real funds and positions. In a brokerage context, missing an explicit real-trade warning materially increases the risk of accidental financial loss, especially if an agent treats the commands as routine automation steps.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The authentication examples show direct use of account credentials, API keys, and certificate paths/passwords without a nearby warning about secret handling, redaction, or secure input methods. In an agent setting, this can lead users or downstream systems to paste sensitive secrets into prompts, logs, shell history, or telemetry, creating credential theft and account-compromise risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.