Back to skill

Security audit

Signal Generator

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent trading-signal generator that fetches public market data and writes local signal output, with disclosed but notable caveats around optional alerting, cron scheduling, and a local /root dependency.

Before installing, verify that any /root/quant-trading-bot environment on your system is trusted, and only add the cron entry if you want recurring execution. Do not assume Discord or Telegram alerts are sent by this package alone; if you connect a separate messaging wrapper, use dedicated channels and understand that trading signal details may be shared with those third-party services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
85% confidence
Finding
The README explicitly promotes sending automated trading alerts to Discord and Telegram but does not disclose that market data, signal contents, symbols, timestamps, and potentially strategy-derived information will be transmitted to third-party platforms. This is a real transparency and privacy issue because users may enable external notifications without understanding the data-sharing implications, though the exposed data appears limited to trading telemetry rather than secrets.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documentation clearly states that trading signals are automatically sent to Discord and Telegram, but it does not provide a prominent warning that market activity, symbols, timing, and possibly user-specific trading preferences will be transmitted to third-party services. This creates a real data-sharing and privacy risk because users may enable the skill without understanding that external messaging platforms receive trading-related information.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.