NASDAQ Public API CLI

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Nasdaq market-data helper that makes disclosed public API requests and shows no hidden data access, persistence, or destructive behavior.

Reasonable to install if you want an agent to fetch public Nasdaq screener data. Be aware it may run a local Bash script that makes external requests to Nasdaq, so review the script and use sensible pagination or rate limits if publisher provenance matters to you.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill directs the agent to execute a bundled shell script, but the skill manifest does not declare shell/code-execution permissions. This creates a capability mismatch that can bypass operator expectations and policy controls, increasing the chance that networked script execution occurs without proper review.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal