IBKR CLI

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Interactive Brokers trading skill, but it can place live brokerage orders without clear built-in confirmation or dry-run safeguards.

Review carefully before installing. Prefer paper trading first, verify which IBKR account and port it uses, and avoid allowing automated or ambiguous prompts to run order-placement commands unless you have added your own confirmation, size limits, and dry-run workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly documents live-capable trading actions such as place-order and cancel-order without any prominent warning, simulation-first guidance, or confirmation requirements. In a brokerage context, this materially increases the chance of accidental live trades, unwanted order cancellation, and financial loss, especially because the commands are presented as straightforward operational examples.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
This wrapper can directly place live brokerage orders by forwarding CLI arguments to the underlying order-placement command without any explicit confirmation, dry-run mode, or safety interlock in this file. In a trading skill, that increases the chance of accidental or unintended execution from user mistakes, automation errors, or prompt/argument confusion, which can cause immediate financial loss.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal