Strategy Deployer

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only trading deployment skill with visible risk controls, but users should fix its malformed trigger configuration and treat live trading use as financially sensitive.

Before installing, verify that this publisher is the one you intended to trust, fix the malformed triggers so the skill activates only in clearly intended trading-deployment contexts, keep paper mode as the default, and require explicit human approval plus platform-level broker controls before any live trading action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger configuration is malformed as `System.Object[]`, which does not define concrete activation conditions for the skill. In a deployment-oriented skill that can promote trading strategies, ambiguous or broken trigger parsing can cause unintended activation behavior, bypass expected operator review, or disable safeguards that depend on correct trigger semantics.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal