PyWenCai Stock

Security checks across malware telemetry and agentic risk

Overview

This is a coherent stock-data lookup skill, but users should avoid its documented SSL-verification workaround.

Install only if you are comfortable sending stock-query text to pywencai/Tonghuashun Wencai. Do not use the SSL workaround that disables certificate verification; fix certificates or dependency versions instead. Avoid submitting proprietary trading research or sensitive watchlists, and run the example only in an environment where /tmp/mootdx cannot be controlled by someone else.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The troubleshooting example explicitly shows how to disable SSL certificate verification by replacing the default HTTPS context with an unverified one. Even though it is labeled 'not recommended,' it omits a clear explanation that this enables man-in-the-middle interception and tampering of network traffic, which is especially relevant for a skill that retrieves external financial data over the network.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal